Malware

Jatif.627 (B) malicious file

Malware Removal

The Jatif.627 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jatif.627 (B) virus can do?

  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
api.ip138.com
a.tomx.xyz
dwoncdn.xiald.com
down.xiald.com
dwoncdn2.xiald.com
67960.png
www.9973.com
xzqtj.xiald.com

How to determine Jatif.627 (B)?


File Info:

crc32: 4D3470C9
md5: 3045e802e3b87fa7dd7a7955863170dd
name: 1515v4.0_84_67960.exe
sha1: eb009a5b6e4f62b17fc6b2da9ea56f629bdb749e
sha256: 46de09913c2666614ea9b884eebf78b65ea25f22324c1c178c8ea3694d04016c
sha512: 5828b5f17b7b9d40cb96d87b6b734eaf4a8a8ee1c27bed7acf8da75528266ef29bb7fa29d6fbe3d2f158fb4c4aa9234204b8b6bf28759cf4a2be6e303c777c35
ssdeep: 49152:vdl+eisTK2U7bWCyRdRXMYz72HJO3vgVh:GeisO2JCyRdhze
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x9ad8x901fx4e0bx8f7dx5668
FileVersion: 1.6.2.20224
CompanyName: x9ad8x901fx4e0bx8f7dx5668
ProductName: x9ad8x901fx4e0bx8f7dx5668
ProductVersion: 1,6,2,20224
FileDescription: x9ad8x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Jatif.627 (B) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Jatif.627
McAfeePUP-XJH-QB
SangforMalware
K7AntiVirusAdware ( 004d97001 )
BitDefenderGen:Variant.Jatif.627
K7GWAdware ( 004d97001 )
TrendMicroTROJ_GEN.R002C0PBR20
TrendMicro-HouseCallTROJ_GEN.R002C0PBR20
GDataGen:Variant.Jatif.627
Kasperskynot-a-virus:AdWare.Win32.Agent.xxysxq
AlibabaAdWare:Win32/Softcnapp.304f805b
ViRobotAdware.Softcnapp.2220968
RisingAdware.Downloader!1.BBEC (CLOUD)
Ad-AwareGen:Variant.Jatif.627
EmsisoftGen:Variant.Jatif.627 (B)
ComodoMalware@#kwt42mlpjh15
DrWebAdware.Softcnapp.119
Invinceaheuristic
McAfee-GW-EditionPUP-XJH-QB
SentinelOneDFI – Suspicious PE
FireEyeGen:Variant.Jatif.627
SophosGeneric PUA OL (PUA)
APEXMalicious
CyrenW32/Trojan.ESIT-1639
JiangminAdware.Agent.alsi
Endgamemalicious (high confidence)
ArcabitTrojan.Jatif.627
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.xxysxq
MicrosoftPUA:Win32/CoinMiner
VBA32BScope.Adware.Puwaders
ALYacGen:Variant.Jatif.627
MAXmalware (ai score=84)
MalwarebytesPUP.Optional.Softcnapp
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
TencentWin32.Adware.Agent.Lgjl
eGambitUnsafe.AI_Score_81%
FortinetRiskware/Generic_PUA_OL
AVGWin32:AdwareX-gen [Adw]
AvastWin32:AdwareX-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Jatif.627 (B)?

Jatif.627 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment