Malware

Jaik.87534 removal instruction

Malware Removal

The Jaik.87534 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.87534 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Jaik.87534?


File Info:

name: B15085ED075D54F538F4.mlw
path: /opt/CAPEv2/storage/binaries/2470cd27a383903e6dfbdab2f533e7add2614f1956499416dbfc8a58d6c09905
crc32: 3EB2CC45
md5: b15085ed075d54f538f4449551676040
sha1: 61cc045b9f75df3ab50d43015934edb18f609f02
sha256: 2470cd27a383903e6dfbdab2f533e7add2614f1956499416dbfc8a58d6c09905
sha512: 3e1293edcbe92ea02e5f795df3b05134513345172de26dc1f6f1e8af6d334557e0da4dc0bcc6b666d30b3fca5f0663dbb301767b3b02e180c4e2fc12b2386345
ssdeep: 24576:gp84kxSrDSEikfboaATHCppukVCE4+9U/VuwsJnAuVhNZGP5wmklnJl9OJ:SuS3SEdlMHCpppVP4wU/N0nA2Nc5klDW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3652399AACA9AE6F2051435264A71B9E62F701203173CF09D1AE4F6BE397C74F4170E
sha3_384: e5b094a05ce97eb16cd0292ff602b23ae47217291811f329b5488ad08fa12835da5497cc28496089b1280c549d5bbb7d
ep_bytes: 60be005053008dbe00c0ecff66818794
timestamp: 2022-07-19 15:49:25

Version Info:

CompanyName:
FileDescription: RspbugReoirt
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
OriginalFilename:
ProductName: RspbugReoirt
ProductVersion: 1.0.0.0
BuildTool: FlexBuild
Translation: 0x0804 0x03a8
LegalTrademarks:
Comments:

Jaik.87534 also known as:

MicroWorld-eScanGen:Variant.Jaik.87534
FireEyeGeneric.mg.b15085ed075d54f5
CylanceUnsafe
BitDefenderThetaGen:NN.ZelphiF.34806.xnKfa44!!1bj
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/QQWare.DM
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Jaik.87534
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Agentb.Pcrw
Ad-AwareGen:Variant.Jaik.87534
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Jaik.87534 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Agent.CNA5TJ
Antiy-AVLTrojan/Generic.ASMalwS.52D4
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!B15085ED075D
MAXmalware (ai score=89)
VBA32BScope.Trojan.Hesv
MalwarebytesMalware.AI.4266788893
APEXMalicious
RisingStealer.QQPass!1.DE10 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Misc]
Cybereasonmalicious.b9f75d

How to remove Jaik.87534?

Jaik.87534 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment