Malware

Jacard.142618 information

Malware Removal

The Jacard.142618 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.142618 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Jacard.142618?


File Info:

crc32: 86482D3D
md5: 44aee97a98d5b7db5326bb734ff246c4
name: 44AEE97A98D5B7DB5326BB734FF246C4.mlw
sha1: 0125548e3d4e445f57d3a6ead4f59df326e83325
sha256: d9ef6fa3fab8fa4753a7b94fb78e126d23b8be804b75c60db06950dd1e6a5f4c
sha512: 8a8ba93b2ab0a7a50a64bd65665633ebe0a70da4363cdf2adb333dc10fac3071050352c5cc58d0cf6a415ec02056280f7db27e0501ab60459fdca2c780bdbbe9
ssdeep: 12288:zKbEYJHQ1FJl0milUQo+D4bgsXlS92390jp5BhNYZ9bksXGi7:zyEoQ1FJmmil/o+Ow0+dzIbkC7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Jacard.142618 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.KillFiles.63510
CynetMalicious (score: 85)
ALYacGen:Variant.Jacard.142618
CylanceUnsafe
ZillyaTrojan.Agent.Win32.939554
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Jacard.142618
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a98d5b
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan.Win32.Agent.qwhelu
AlibabaTrojan:Win32/Generic.7050da56
NANO-AntivirusTrojan.Win32.KillFiles.fhxmtw
MicroWorld-eScanGen:Variant.Jacard.142618
TencentWin32.Trojan.Agent.Pdcw
Ad-AwareGen:Variant.Jacard.142618
SophosGeneric PUA AB (PUA)
F-SecureTrojan.TR/Agent.qmtza
BitDefenderThetaAI:Packer.A1A97A4819
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R014C0OI920
McAfee-GW-EditionBehavesLike.Win32.BadFile.jc
FireEyeGen:Variant.Jacard.142618
EmsisoftGen:Variant.Jacard.142618 (B)
JiangminTrojan.Agent.bpgy
WebrootW32.Trojan.GenKD
AviraTR/Agent.qmtza
MicrosoftTrojan:Win32/Occamy.CD9
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Jacard.D22D1A
AegisLabTrojan.Win32.Agent.4!c
ZoneAlarmTrojan.Win32.Agent.qwhelu
GDataGen:Variant.Jacard.142618
McAfeeArtemis!44AEE97A98D5
VBA32Trojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0OI920
IkarusTrojan.Agent
FortinetW32/Agent.QWHELU!tr
Paloaltogeneric.ml

How to remove Jacard.142618?

Jacard.142618 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment