Adware

Adware.Jacard.100 (file analysis)

Malware Removal

The Adware.Jacard.100 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Jacard.100 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Executes the printer spooler process
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Behavioural detection: Transacted Hollowing
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Accessed credential storage registry keys
  • Deletes executed files from disk

How to determine Adware.Jacard.100?


File Info:

name: 89C712F96B2129EFD4B9.mlw
path: /opt/CAPEv2/storage/binaries/008c57fd5a2c679afb030b797efb64b6a436aae1a5c0f5d4288d46e814ce737b
crc32: 23CC3A91
md5: 89c712f96b2129efd4b9ab7ac4fa2986
sha1: e5d060ba015e78b3d43f30dfca3e4f644e47d51d
sha256: 008c57fd5a2c679afb030b797efb64b6a436aae1a5c0f5d4288d46e814ce737b
sha512: ab69a99baef7a9db8518e9efcf1d7ef08375db7a0f3f3ae0076e6f398146a44e28b748d77a861c18f4af4b1733f05e6586967e0ffc9f951c1e79d7f5f0c7b211
ssdeep: 24576:kx8uIwqxKZuf3fivESEmFHVHj3Bhxgju:9uDQfG9dhxg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B257E11F3818937D1231A3DCD1B53A59939BE502F389A4B7BF62E0C6F3A68179252D3
sha3_384: 4e6e66a686b639f335b14c3ac07e3a7853576e4091dca67fe14eba60f51fe7a77b3521946efb77f9daf95e9acc77ed6f
ep_bytes: 558becb9790000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: AADS WorldWide LTD
FileDescription: Enterprise - Demo
FileVersion: 7.3.153.20
InternalName: Enterprise - Demo
LegalCopyright: AADS WorldWide LTD
LegalTrademarks: AADS WorldWide LTD
OriginalFilename: Enterprise - Demo
ProductName: Enterprise - Demo
ProductVersion: 7.3
BuildDate: 20-Sep-2018 11:21:54.695
Translation: 0x0409 0x04e4

Adware.Jacard.100 also known as:

LionicTrojan.Win32.Agent.4!c
FireEyeGeneric.mg.89c712f96b2129ef
McAfeeArtemis!89C712F96B21
CylanceUnsafe
ZillyaDropper.Agent.Win32.386453
Sangfor[INNO_1]
AlibabaTrojanDropper:Win32/BScope.78c7783c
Cybereasonmalicious.96b212
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.FGVYFKV
APEXMalicious
ClamAVWin.Malware.Jacard-9881867-0
BitDefenderGen:Variant.Adware.Jacard.100
NANO-AntivirusTrojan.Win32.KillFiles.fodoai
MicroWorld-eScanGen:Variant.Adware.Jacard.100
AvastWin32:Malware-gen
TencentWin32.Trojan-dropper.Agent.Ednz
Ad-AwareGen:Variant.Adware.Jacard.100
EmsisoftGen:Variant.Adware.Jacard.100 (B)
ComodoMalware@#2fiv9iwaiblg5
DrWebTrojan.KillFiles.63991
VIPREGen:Variant.Adware.Jacard.100
McAfee-GW-EditionBehavesLike.Win32.Worm.dh
SophosGeneric PUA OF (PUA)
IkarusTrojan.Dropper.Agent
GDataGen:Variant.Adware.Jacard.100
WebrootW32.Trojan.Gen
AviraTR/Drop.Agent.xehyl
Antiy-AVLTrojan/Generic.ASMalwS.6
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.C2768603
ALYacGen:Variant.Adware.Jacard.100
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002H0CH322
RisingTrojan.Generic@AI.81 (RDML:J9Gua4c6QhfprTMuzT0ucg)
FortinetW32/Agent!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Adware.Jacard.100?

Adware.Jacard.100 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment