Malware

How to remove “JokeTool.ScreenMate”?

Malware Removal

The JokeTool.ScreenMate is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JokeTool.ScreenMate virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine JokeTool.ScreenMate?


File Info:

name: 9AE9281769FE5DC037D1.mlw
path: /opt/CAPEv2/storage/binaries/288bf178be0b2b51c66b6662ccfc9c2ab9418207e5485b74cbc3f5d2286b9b0f
crc32: D4F55302
md5: 9ae9281769fe5dc037d112ffc5ecf2f5
sha1: 0dacb4f15715be89fb57dbc0a306047b3a4e3a24
sha256: 288bf178be0b2b51c66b6662ccfc9c2ab9418207e5485b74cbc3f5d2286b9b0f
sha512: 20f54837aa22b74670d895955d69281404d42bd2d085967534e2e0135df6ea8cd751610bab24640a90d35f916f1dc734f882b5b56f3ea0cadf4098ee89d5b853
ssdeep: 6144:MGvApOg6s1X3SNKArS+0sJu1A/6mZ356iPp2HcHJ7J7J7J7Z:tYp/fSprSXsJu1AtDI8HJ7J7J7J7Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB44BF053A8241EAD0E0177118DB2BF1573EBEBB2A7AAD9FD34CE8194DD2104D64277E
sha3_384: 71495e5a35b9de55f84fba4e87dafcd86ded0525ac871f451abf8daddbbd047b969e0feab1ba6fb9bbb3dc181a7c3a6a
ep_bytes: 558bec6aff68d053410068903a400064
timestamp: 2000-05-19 14:23:49

Version Info:

0: [No Data]

JokeTool.ScreenMate also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Generic.32097122
FireEyeGeneric.mg.9ae9281769fe5dc0
CAT-QuickHealTrojan.GenericPMF.S449430
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.110899
SangforJoke.Win32.Screenmate.Vamp
K7AntiVirusUnwanted-Program ( 004ba4541 )
K7GWUnwanted-Program ( 004ba4541 )
CyrenW32/ABJoke.NQOE-2491
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Joke.ScreenMate.AA potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PKG22
BitDefenderTrojan.Generic.32097122
CynetMalicious (score: 100)
SUPERAntiSpywarePUP.ScreenMate/Variant
AvastFileRepPup [PUP]
Ad-AwareTrojan.Generic.32097122
SophosGeneric ML PUA (PUA)
VIPRETrojan.Generic.32097122
TrendMicroTROJ_GEN.R002C0PKG22
McAfee-GW-EditionGenericRXSG-CG!9AE9281769FE
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Generic.32097122 (B)
GDataTrojan.Generic.32097122
JiangminTrojan/Refroso.aoiq
AviraJOKE/ScreenMate.vnqbd
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D1E9C362
ViRobotAdware.Screenmate.270336.F
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Malware/Win.AGEN.C4588116
McAfeeGenericRXSG-CG!9AE9281769FE
MalwarebytesJokeTool.ScreenMate
RisingTrojan.Generic@AI.100 (RDML:UHT8todRzHFHMmcbTqILHA)
YandexTrojan.GenAsa!XzvthfJ8cnU
IkarusTrojan.Rogue
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/ScreenMate
AVGFileRepPup [PUP]
CrowdStrikewin/grayware_confidence_70% (W)

How to remove JokeTool.ScreenMate?

JokeTool.ScreenMate removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment