Malware

About “Jaik.83892” infection

Malware Removal

The Jaik.83892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.83892 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the njRat malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Jaik.83892?


File Info:

name: 314B77594CB7798525A3.mlw
path: /opt/CAPEv2/storage/binaries/7e6315a18e7fb6aab87b3e7c6b6c5828ed28614bb80715b65de98421d67c1a75
crc32: C6AE2759
md5: 314b77594cb7798525a343544c57146a
sha1: 3a18572e0320ac45cca2d626acb1afbc9f6e1724
sha256: 7e6315a18e7fb6aab87b3e7c6b6c5828ed28614bb80715b65de98421d67c1a75
sha512: 302a026c865d80a34079459ae822e6c81fccbec43bc3141f2e42082c0cde2dd9f070f4c4344697c6a4ab053a4f7abe4976a3f44748f8e185ab334ee6ebab26d4
ssdeep: 6144:4jo7bWFgG+oaZsHQvgLviusp+iPlIs59Lm2Pzqvr7P1L:pkgG+LswvgLaciPV9lPzwr7P5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19044238E19DDED52CE5C443FD02EBBAC21021F76DF94C85A92B106E4EB2839F3E85459
sha3_384: 28a8a8d979ac3c15beb28e00330625c02b4dc120ba76064b7a034cd02518c611ef7b664967a5b5c46441c0298c4e1b44
ep_bytes: eb042044e8e150eb020fffe817000000
timestamp: 2022-08-12 22:45:06

Version Info:

0: [No Data]

Jaik.83892 also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
FireEyeGeneric.mg.314b77594cb77985
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.e0320a
CyrenW32/Virut.AI!Generic
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
KasperskyVHO:Backdoor.MSIL.SpyGate.gen
BitDefenderGen:Variant.Jaik.83892
MicroWorld-eScanGen:Variant.Jaik.83892
RisingTrojan.Generic@AI.100 (RDML:NpDwERCjzvAfZSrIwEkgEg)
Ad-AwareGen:Variant.Jaik.83892
EmsisoftGen:Variant.Jaik.83892 (B)
VIPREGen:Variant.Jaik.83892
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusBackdoor.MSIL.Bladabindi
GDataGen:Variant.Jaik.83892
AviraHEUR/AGEN.1216959
ArcabitTrojan.Jaik.D147B4
ZoneAlarmVHO:Backdoor.MSIL.SpyGate.gen
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GoogleDetected
Acronissuspicious
VBA32BScope.Trojan.APosT
ALYacGen:Variant.Jaik.83892
MAXmalware (ai score=81)
MalwarebytesMalware.Heuristic.1003
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34592.qqX@a4WNmVo
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Jaik.83892?

Jaik.83892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment