Malware

Jacard.141311 removal guide

Malware Removal

The Jacard.141311 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.141311 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese
  • Installs itself for autorun at Windows startup

Related domains:

abrilprorock2018.webcindario.com
hoteldobook2018.webcindario.com

How to determine Jacard.141311?


File Info:

crc32: CFF4CCCE
md5: ec337c4b99e76f8a0e6d2f6ff9dea8a7
name: EC337C4B99E76F8A0E6D2F6FF9DEA8A7.mlw
sha1: 3ffdaecce93339110079cb73ec39d5a3bd5e9ef2
sha256: 71dddf38e4919faa71160feb4cdaeb4bc29c0ab1bbc1e50ec91ee0efa5bc3a22
sha512: dac6346782464be3a035c42d5140251e2c518c4492c04cd6e726a86abb02927675f5ccc0717154c4fefdcd839aed03e919f9152858c2a344c7b680a429ef3513
ssdeep: 49152:AQySfNIJR0HVimQF+3DRP1TbkOP6Afe1zKBh1Y8M7zAv5oR6EY:2R01imQF+3DRGe8KBPdhoR6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Jacard.141311 also known as:

K7AntiVirusSpyware ( 0050ba8c1 )
LionicTrojan.Win32.BestaFera.4!c
MicroWorld-eScanGen:Variant.Jacard.141311
CAT-QuickHealTrojan.BestaFera
ALYacGen:Variant.Jacard.141311
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Banker.2b41a293
K7GWSpyware ( 0050ba8c1 )
Cybereasonmalicious.b99e76
TrendMicroTROJ_GEN.R03FC0WDF19
NANO-AntivirusTrojan.Win32.BestaFera.fpacxm
CyrenW32/Trojan.KQNU-1611
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.ADUT
AvastWin32:Trojan-gen
GDataGen:Variant.Jacard.141311
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderGen:Variant.Jacard.141311
Ad-AwareGen:Variant.Jacard.141311
SophosMal/Generic-S
F-SecureBackdoor.BDS/Hupigon.Gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.ec337c4b99e76f8a
EmsisoftGen:Variant.Jacard.141311 (B)
SentinelOneDFI – Suspicious PE
Endgamemalicious (high confidence)
AviraBDS/Hupigon.Gen
Antiy-AVLTrojan[Banker]/Win32.BestaFera
MicrosoftTrojan:Win32/Occamy.C
JiangminTrojan.Banker.BestaFera.fsv
ArcabitTrojan.Jacard.D227FF
ZoneAlarmHEUR:Trojan-Banker.Win32.BestaFera.gen
AhnLab-V3Malware/Gen.Generic.C2921650
McAfeeArtemis!EC337C4B99E7
MAXmalware (ai score=99)
VBA32BScope.Trojan.Occamy
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03FC0WDF19
RisingSpyware.Banker!8.8D (TFE:4:MEYmCR8I0ZC)
YandexTrojanSpy.Banker!UqFUGj/AXMQ
IkarusTrojan-Spy.Agent
FortinetW32/Banker.ADUT!tr.spy
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.95b

How to remove Jacard.141311?

Jacard.141311 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment