Malware

Jatif.1973 removal tips

Malware Removal

The Jatif.1973 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jatif.1973 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Network activity contains more than one unique useragent.

How to determine Jatif.1973?


File Info:

crc32: 10F6D551
md5: 8079f698e32f322b612a4dcf5f0c2ad9
name: 8079F698E32F322B612A4DCF5F0C2AD9.mlw
sha1: 1c7f98ded5236e53ed2e0be9ee9ca11378ebaa4d
sha256: 64f78697633fcd61fa5ad040afa1fc6fedf1ff2a70f8dfb408dc8f29970dfef1
sha512: 6092845007cb00cd8d923ea5f93aa9b83cb9047c375a0b14830c2c9029595d25e88e8be057d439bc33460997c9fe5ba995c46fd662e51a70cc2f48eae84a5369
ssdeep: 6144:W8Q+bwM18+SW18ebBNVgV4OJbo9/uwcB/YcAOzZ230PRySE/fPC:W8vb51591/bBNUo9/uwcB/Yc630C/fa
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Jatif.1973 also known as:

MicroWorld-eScanGen:Variant.Jatif.1973
FireEyeGen:Variant.Jatif.1973
CAT-QuickHealTrojan.Cometer
ALYacTrojan.Agent.CobaltStrike
AegisLabTrojan.Win32.Cometer.4!c
SangforMalware
K7AntiVirusTrojan ( 005752431 )
BitDefenderGen:Variant.Jatif.1973
K7GWTrojan ( 005752431 )
Cybereasonmalicious.8e32f3
CyrenW32/Trojan.VHDF-1876
SymantecTrojan.Gen.2
KasperskyHEUR:Trojan.Win32.Cometer.gen
AlibabaTrojan:Win32/Cometer.a6f8c065
NANO-AntivirusTrojan.Win32.Cometer.idnvgz
RisingTrojan.Generic@ML.83 (RDMK:EorKJu7YYAyMci6sSVMaXw)
Ad-AwareGen:Variant.Jatif.1973
SophosGeneric PUA BM (PUA)
ComodoMalware@#3fcpkiokot5ge
F-SecureTrojan.TR/Swrort.zceqf
DrWebBackDoor.Meterpreter.168
ZillyaTrojan.Cometer.Win32.2404
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert-S.DO (A)
IkarusTrojan.Swrort
JiangminTrojan.Cometer.bmb
AviraTR/Swrort.zceqf
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA64
GridinsoftTrojan.Win32.Gen.oa
ArcabitTrojan.Jatif.D7B5
ZoneAlarmHEUR:Trojan.Win32.Cometer.gen
GDataGen:Variant.Jatif.1973
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.CobaltStrike.R357702
McAfeeArtemis!8079F698E32F
PandaTrj/CI.A
ESET-NOD32Win32/Rozena.AZH
TrendMicro-HouseCallTROJ_GEN.R023H07KP20
FortinetPossibleThreat.MU
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.44b

How to remove Jatif.1973?

Jatif.1973 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment