Ransom Trojan

Trojan-Ransom.Win32.Jaff.az (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Jaff.az is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Jaff.az virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Anomalous binary characteristics

Related domains:

globallistionintyrtg.com

How to determine Trojan-Ransom.Win32.Jaff.az?


File Info:

crc32: 6FF66B57
md5: d349764bd5e16ee0e202b1e9dc057318
name: D349764BD5E16EE0E202B1E9DC057318.mlw
sha1: 2c6861b942341e193b633cf01755ad6660e117e0
sha256: dd6e62e4c82170b42b515e4c25cba3c2cc95b44c032c844208de77172cac084d
sha512: d1c46c00f51f537680dceec8b7fe596f5a5633065cabe06e5204d5c8632288bdc2fa62536105925f01125805c77a44d46730834eab3f7a080cff31e6eafbce27
ssdeep: 1536:+rKfHeOlyx+g6QWYyS8QWqDind1wjSfz7tTgwcXJ4+:qJOMgg6QW3pQWqDcdlvPcX3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Jaff.az also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Scatter.toP1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.12062
CAT-QuickHealRansom.Exxroute.A4
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5341
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Jaffrans.b0546a75
K7GWTrojan ( 0050e87d1 )
K7AntiVirusTrojan ( 0050e87d1 )
CyrenW32/Cerber.XBRF-0727
SymantecRansom.Jaff
ESET-NOD32Win32/Filecoder.Jaff.B
ZonerTrojan.Win32.56181
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Jaff.az
BitDefenderTrojan.GenericKD.5283070
NANO-AntivirusTrojan.Win32.Filecoder.exkcee
ViRobotTrojan.Win32.Jaff.83968
MicroWorld-eScanTrojan.GenericKD.5283070
TencentMalware.Win32.Gencirc.114b092d
Ad-AwareTrojan.GenericKD.5283070
SophosMal/Generic-R + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Cerber.FTKN@7dx0qc
BitDefenderThetaGen:NN.ZexaF.34170.fqW@aOwFW5ei
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPJAFF.WLV
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeTrojan.GenericKD.5283070
EmsisoftTrojan.GenericKD.5283070 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scatter.ei
WebrootW32.Ransomware.Jaff
AviraTR/Crypt.XPACK.pgzfq
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.2090D12
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Generic.D509CFE
SUPERAntiSpywareRansom.JaffCrypt/Variant
ZoneAlarmTrojan-Ransom.Win32.Jaff.az
GDataWin32.Trojan.Agent.FZNIXT
TACHYONRansom/W32.Scatter.83968
AhnLab-V3Trojan/Win32.Scatter.C1993290
Acronissuspicious
McAfeeGeneric.acf
MAXmalware (ai score=100)
VBA32Trojan.FakeAV.01657
MalwarebytesTrojan.MalPack.VAK
PandaTrj/WLT.C
TrendMicro-HouseCallRansom_CRYPJAFF.WLV
RisingTrojan.Generic@ML.100 (RDML:sEr7bizzsbFEsVjsBg1Usw)
YandexTrojan.GenAsa!rCvSgp5A8ks
IkarusTrojan.Inject
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Jaff.az?

Trojan-Ransom.Win32.Jaff.az removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment