Virus

Virus:Win32/Jadtre.L (file analysis)

Malware Removal

The Virus:Win32/Jadtre.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Jadtre.L virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Jadtre.L?


File Info:

name: A577CB094575C685D88F.mlw
path: /opt/CAPEv2/storage/binaries/00c8bbf101f09bc019b682d17bcbae14b4aa7d39f8431d421d7f6faff38b0bc5
crc32: 0288AA6C
md5: a577cb094575c685d88f3d1c777e32a0
sha1: 0fdad7dd7c031fa5fa641db187db4145ed116ce6
sha256: 00c8bbf101f09bc019b682d17bcbae14b4aa7d39f8431d421d7f6faff38b0bc5
sha512: 7e1738b15c43a84345450de034888eff651b86ce22d5680d6ae7841a963cb81683827d3f50bc391e8accd624930e321728001b04da1454056b2edecf128270b2
ssdeep: 12288:jqOPajQUXXP8QvLWFx6Mo5rippDC7ee1hpls4Ey+UDH/MW/Wm7MDgTuaZxZMma:jnajQEPnvg6PhWDC750cJt7kgqSM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194556C90F2C1C4B6D49711724DAADA3021A7BE588B7497DF615E370D9AB33C3247AF0A
sha3_384: 9636ab0e2e13ec0a44c7eaff7a4d95275d74478e5b6b7d90ede3ba25cf729ae66f70de1f6b92bd4b14ab2f0ae94ecb02
ep_bytes: 558bec81ec84000000c745ec00aa0300
timestamp: 2006-08-28 07:08:09

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Help Viewer
FileVersion: 1.0.0.185
InternalName: Adobe Help Viewer
LegalCopyright: (C) 2006 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: ahv.exe
ProductName: Adobe Help Viewer
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Virus:Win32/Jadtre.L also known as:

BkavW32.QvodInfect.PE
LionicVirus.Win32.Nimnul.lmra
DrWebWin32.Rmnet.5
MicroWorld-eScanWin32.Qvod.C
ClamAVWin.Trojan.Loorp-1
FireEyeGeneric.mg.a577cb094575c685
CAT-QuickHealW32.Numnul.C
SkyhighBehavesLike.Win32.Generic.th
McAfeeW32/Simfect.f
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Qvod.C
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 001ab60e1 )
AlibabaMalware:Win32/km_2c613c9.None
K7GWVirus ( 001ab60e1 )
Cybereasonmalicious.d7c031
ArcabitWin32.Qvod.C
BitDefenderThetaAI:FileInfector.991137D00F
VirITWin32.Nimul.C
SymantecW32.Loorp.C!inf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Wapomi.AE
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Nimnul.c
BitDefenderWin32.Qvod.C
NANO-AntivirusVirus.Win32.Otwycal.durta
AvastWin32:GenMalicious-GSA [Trj]
TencentVirus.Win32.Dropper.a
EmsisoftWin32.Qvod.C (B)
F-SecureMalware.W32/Nimnul.C
BaiduWin32.Virus.Otwycal.c
ZillyaVirus.Nimnul.Win32.1
TrendMicroPE_NIMNUL.A
SophosW32/Jadtre-G
IkarusTrojan-Dropper.Win32.Bototer
JiangminWin32/Qvod.a
GoogleDetected
AviraW32/Nimnul.C
Antiy-AVLVirus/Win32.Nimnul.c
KingsoftWin32.Qvod.aa.5756
XcitiumVirus.Win32.Nimnul.C@23r7wu
MicrosoftVirus:Win32/Jadtre.L
ViRobotWin32.Qvod.D
ZoneAlarmVirus.Win32.Nimnul.c
GDataWin32.Qvod.C
VaristW32/Nimnul.A
AhnLab-V3Win32/Qvod
Acronissuspicious
VBA32Virus.Nimnul.d
ALYacWin32.Qvod.C
Cylanceunsafe
PandaW32/Qvod.A
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_NIMNUL.A
RisingWin32.Yxi.a (CLASSIC)
YandexWin32.Nimnul.Gen
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Nimnul.C
FortinetW32/Nimnul.C
AVGWin32:GenMalicious-GSA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Jadtre.L?

Virus:Win32/Jadtre.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment