Malware

Jaik.90396 information

Malware Removal

The Jaik.90396 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jaik.90396 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Farsi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects BullGuard Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Anomalous binary characteristics

How to determine Jaik.90396?


File Info:

name: 770D596F30D2F5D784A7.mlw
path: /opt/CAPEv2/storage/binaries/1b9e4fcf838940194673a3bee14e67b5798cf85200a0d3e0a66d4fb477fe5cea
crc32: C8F703B4
md5: 770d596f30d2f5d784a7601f9f7d407e
sha1: 30f62198fa78df64ad4afeeeee488b747209415d
sha256: 1b9e4fcf838940194673a3bee14e67b5798cf85200a0d3e0a66d4fb477fe5cea
sha512: ef9e86dc714c849fd9d913350606871cdc44824163533b2c24fe6574937fc7ae31f05cd749e3f9b8b8397af28bb6e33593789f819dfcaceee80bea44943d42a4
ssdeep: 49152:/mGhk8UUyG4JED/URkqCxsfhw8fhTdwLtQpsqMWLrNfh0se:+GpyGtD/U2qCxsJXfldqQpsqMG2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A195F0A3BD44C1DFCB632738AC45CB782A11E89EDA20B3C596A5639FD5743F24638E14
sha3_384: 401709e0a6855fcdb816b56a6c49b792019cd5f8eb1b7c32e337d8b60c419332f796994c2c5baea2d5238412d1ab5e47
ep_bytes: e8d7470000e989feffff660fefc05153
timestamp: 2019-07-09 08:21:04

Version Info:

0: [No Data]

Jaik.90396 also known as:

MicroWorld-eScanGen:Variant.Jaik.90396
FireEyeGeneric.mg.770d596f30d2f5d7
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQJQ
APEXMalicious
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Jaik.90396
Ad-AwareGen:Variant.Jaik.90396
EmsisoftGen:Variant.Jaik.90396 (B)
IkarusTrojan-Spy.Agent
GDataGen:Variant.Jaik.90396
ArcabitTrojan.Jaik.D1611C
ZoneAlarmVHO:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MAXmalware (ai score=83)
MalwarebytesMachineLearning/Anomalous.95%
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen

How to remove Jaik.90396?

Jaik.90396 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment