Malware

What is “Jacard.13238”?

Malware Removal

The Jacard.13238 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.13238 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Jacard.13238?


File Info:

crc32: 430B20D5
md5: 26778b995b0e7ea86c8e89e2c2cc4e30
name: 26778B995B0E7EA86C8E89E2C2CC4E30.mlw
sha1: 4555365ffa0ab461f6f8a005d1a0db4d3067ef67
sha256: dcbc182173b06dce19426bea023c521222df2bbf2222edc6d36943f03288de55
sha512: 37bf1dd10e62e4956b444600c1cae8fe511fec3fbb88d9b8a882f2a54c44c2f0474b3c6149158fff4a0cf9322c331f73136f72216ca23c09567a42e0f57d8ffa
ssdeep: 24576:X24gsa6Qb1kXGxFAAhQhwszj+kve5LqZEB72ks0rTdq:m4gsvQb1k28nwsnNEIDWTI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1984-2016 Adobe Systems Incorporated and its licensors. All rights reserved.
InternalName: Adobe Acrobat Reader DX
FileVersion: 10.7.20033.13737
ProductName: Adobe Acrobat Reader DX
ProductVersion: 10.7.20033.13737
FileDescription: Adobe Acrobat Reader DX
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Jacard.13238 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.13238
FireEyeGeneric.mg.26778b995b0e7ea8
McAfeeGenericRXAA-FA!26778B995B0E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 004e02ad1 )
BitDefenderGen:Variant.Jacard.13238
K7GWTrojan-Downloader ( 004e02ad1 )
Cybereasonmalicious.95b0e7
BitDefenderThetaAI:Packer.E19542C118
CyrenW32/Trojan.LDAJ-6031
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.BYK
APEXMalicious
AvastWin32:Delf-UFQ [Trj]
KasperskyTrojan-Downloader.Win32.Rakhni.krx
NANO-AntivirusTrojan.Win32.Rakhni.emjeda
AegisLabTrojan.Win32.Rakhni.a!c
RisingDownloader.Gendwnurl!8.D8D6 (TFE:4:JA2eR7x6PuI)
Ad-AwareGen:Variant.Jacard.13238
SophosMal/Generic-S (PUA)
ComodoMalware@#3e70tkdqlhrm0
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.DownLoader24.62972
ZillyaDownloader.Rakhni.Win32.223
McAfee-GW-EditionGenericRXBB-LA!3FD93394035B
EmsisoftGen:Variant.Jacard.13238 (B)
IkarusTrojan-Downloader.Win32.Rakhni
JiangminTrojan.Bcex.ih
AviraTR/Downloader.Gen7
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Bcex
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Jacard.D33B6
AhnLab-V3Downloader/Win32.Delf.C1783347
ZoneAlarmTrojan-Downloader.Win32.Rakhni.krx
GDataGen:Variant.Jacard.13238
CynetMalicious (score: 85)
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jacard.13238
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b3a92b
YandexTrojan.GenAsa!B4SWzjBtgJ4
SentinelOneStatic AI – Malicious PE – Installer
eGambitUnsafe.AI_Score_88%
FortinetW32/Dloader.CDW!tr
AVGWin32:Delf-UFQ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.b19

How to remove Jacard.13238?

Jacard.13238 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment