Malware

Jatif.1502 (B) removal

Malware Removal

The Jatif.1502 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jatif.1502 (B) virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Jatif.1502 (B)?


File Info:

name: BFBD55F30D185FB63170.mlw
path: /opt/CAPEv2/storage/binaries/2a6c0875208e6b0f2c6d30f006bd1a76e13b92bc506f1c155332008041c7ca25
crc32: 2D42C9C5
md5: bfbd55f30d185fb6317082a3f0309c9a
sha1: 4e39ea56f4ffc83cd547280facf1bd22b49566cb
sha256: 2a6c0875208e6b0f2c6d30f006bd1a76e13b92bc506f1c155332008041c7ca25
sha512: 591c4af03616a9f087f17b7cc5e9cfbf6643d91e3362c7fd6840d8bcbe505cca1678e06be50770cc6431d3e1bc56b322f5963ce72c5dbcb6ae6549794d94c8a7
ssdeep: 3072:BLuXzXwYyr6DoocPpKzPufPi4iIlbO8jtBgc5HPdx6/4s:Bpl4PufrllbtM4vdkd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135C3F182ABB0C5F7EE02063059F9A73BDFBA670461504F4B67654E1E7D813D28B2E207
sha3_384: 5f97007cbe6316e11296ceb881ecc8f2886874512c898d2417a1762feb695a800d99f28c39815a5493d6d11cecaa900c
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:52

Version Info:

CompanyName: SoftX Corp
FileDescription: Go Next Setup
FileVersion: 2.4.0.5
LegalCopyright: Copyright 2017 SoftX Corp. All rights reserved.
ProductName: GoNextSetup
ProductVersion: 2.4.0.5
Publisher: SoftX Corp
Translation: 0x0409 0x04e4

Jatif.1502 (B) also known as:

LionicTrojan.Win32.Generic.a!c
DrWebAdware.Downware.18301
MicroWorld-eScanGen:Variant.Jatif.1502
FireEyeGen:Variant.Jatif.1502
McAfeeArtemis!BFBD55F30D18
MalwarebytesAdware.SpecialSearchOffer
SangforRiskware.Win32.Agent.ky
K7AntiVirusAdware ( 005866d21 )
AlibabaTrojanDownloader:Win32/OpenSUpdater.3239735c
K7GWAdware ( 005866d21 )
Cybereasonmalicious.30d185
ArcabitTrojan.Jatif.D5DE
ESET-NOD32Win32/Adware.OpenSUpdater.CF
APEXMalicious
ClamAVWin.Downloader.Sodinokibi-7641635-0
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderGen:Variant.Jatif.1502
NANO-AntivirusTrojan.Win32.Updater.esyupk
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-downloader.Generic.Pkhh
Ad-AwareGen:Variant.Jatif.1502
EmsisoftGen:Variant.Jatif.1502 (B)
ComodoApplicUnwnt@#2gi4haedpthvp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA EO (PUA)
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1110760
MAXmalware (ai score=75)
MicrosoftPUADlManager:Win32/OpenDownloadManager
GDataGen:Variant.Jatif.1502
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Jatif.1502
AVGWin32:Adware-gen [Adw]
PandaPUP/SoftwareUpdater
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Jatif.1502 (B)?

Jatif.1502 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment