Malware

Jaik.80502 removal instruction

Malware Removal

The Jaik.80502 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.80502 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Kannada
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Jaik.80502?


File Info:

name: 7F72CDDFFFE6EE679F82.mlw
path: /opt/CAPEv2/storage/binaries/cc9c6bfe0a88994b387009ac8ac0ad03bef97f3737a2e223b03b054f6a5349c6
crc32: CB495067
md5: 7f72cddfffe6ee679f82e99ffc701aba
sha1: 9d5d48142512e37e5a8ea30d415bcec2b3ff6754
sha256: cc9c6bfe0a88994b387009ac8ac0ad03bef97f3737a2e223b03b054f6a5349c6
sha512: 1200ff94196e168647de9d08e5503bd87929b37295f0ace189a470ad911c93fe4f8a145acfb77616e9749d8b0ba014e2c3cab40e3264c9d0affcdcde0bb93479
ssdeep: 6144:pz6zKCzK9Ax59YZIsCT7SqqLXJMniKpiIKvq2:pmv159OGm/JMnri/q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F264E1127BA28C72D8A6303048F2DE121BBF786166704A8777F8177D9E617D05F7839A
sha3_384: 35731e7f7aa7702eaa99ad3c668f98f4f8b8111bdfc9e6ca32d8cf96d1e1576b5822eb0b2f175c39cb4477951231cfda
ep_bytes: e897520000e989feffff8bff558bec8b
timestamp: 2021-09-14 04:42:38

Version Info:

FileVersions: 29.47.75.83
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 22.82.72.51

Jaik.80502 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
FireEyeGeneric.mg.7f72cddfffe6ee67
McAfeePacked-GDD!7F72CDDFFFE6
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRansomware ( 005532e31 )
K7GWTrojan ( 005649fd1 )
Cybereasonmalicious.42512e
CyrenW32/Kryptik.GVD.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Jaik.80502
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fh
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
MicrosoftRansom:Win32/StopCrypt!ml
CynetMalicious (score: 100)
Acronissuspicious
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@AI.100 (RDML:2v7BI3+VL1ev3TxL8fj4CA)
IkarusTrojan.Crypter
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Jaik.80502?

Jaik.80502 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment