Malware

Should I remove “Jacard.105509”?

Malware Removal

The Jacard.105509 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.105509 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Jacard.105509?


File Info:

name: F2180322F2C1068092A0.mlw
path: /opt/CAPEv2/storage/binaries/b8b9171939a18d72077d12b0a84c1ec6b04efaed4087af5c501a675bd6610ce2
crc32: F6FA0D11
md5: f2180322f2c1068092a09bc4fd3ec450
sha1: 85a98b9dae812347a2d72933e4aed8b5909399a1
sha256: b8b9171939a18d72077d12b0a84c1ec6b04efaed4087af5c501a675bd6610ce2
sha512: 245f718a054202d74e1f4e72f0aa1d2ca56ba7f0e7b646c22be5833eacd0519a23f877a6cb58c1c66652db685f3630acf0b808d64e8b4e9dd840dad82a8b424d
ssdeep: 24576:+W3A5kNLmOL94mPUN78fYWABCS4p4nUJtbk69CdmN9CEI06LWMtMTsnQqbTeniwb:GVxNAq0SHn1mN9QMTm5TenfXCZ5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16EB55B13A382583AD026563B483B97A47D3BFE182A56594F6BB0784CCF392417D2E74F
sha3_384: d2a458622338e04ae519a8a0d1c92906998b42c1426487d6449599a04eb14da250e6fc380fbf8b784e666b39be8482de
ep_bytes: 558bec83c4ec33c08945ecb8349d5a00
timestamp: 2018-01-19 12:37:31

Version Info:

0: [No Data]

Jacard.105509 also known as:

LionicTrojan.Win32.BestaFera.4!c
MicroWorld-eScanGen:Variant.Jacard.105509
FireEyeGeneric.mg.f2180322f2c10680
McAfeeGenericRXDU-JH!F2180322F2C1
CylanceUnsafe
ZillyaTrojan.BestaFera.Win32.6738
SangforTrojan.Win32.BestaFera.aqdr
AlibabaTrojanBanker:Win32/BestaFera.81fa4c62
Cybereasonmalicious.2f2c10
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.YCX
APEXMalicious
KasperskyTrojan-Banker.Win32.BestaFera.aqdr
BitDefenderGen:Variant.Jacard.105509
NANO-AntivirusTrojan.Win32.BestaFera.exfcfy
AvastWin32:Dropper-gen [Drp]
TencentWin32.Trojan-banker.Bestafera.Dzjc
Ad-AwareGen:Variant.Jacard.105509
SophosMal/Generic-S
ComodoMalware@#1vidjb41yt1qw
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Variant.Jacard.105509 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Jacard.105509
AviraHEUR/AGEN.1100793
Antiy-AVLTrojan/Generic.ASMalwS.25100AF
MicrosoftTrojan:Win32/Occamy.CB8
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.C2361305
BitDefenderThetaAI:Packer.A5A45BBF19
ALYacGen:Variant.Jacard.105509
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Banload
MalwarebytesMalware.AI.3910184018
RisingTrojan.Generic@ML.90 (RDML:5rf/LIEjHsza+61WGUxXFA)
YandexTrojan.PWS.BestaFera!DdcV7GoWRhI
IkarusTrojan-Downloader.Win32.Banload
FortinetW32/Banload.YCX!tr.dldr
AVGWin32:Dropper-gen [Drp]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Jacard.105509?

Jacard.105509 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment