Malware

Jacard.147948 removal

Malware Removal

The Jacard.147948 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.147948 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Jacard.147948?


File Info:

crc32: 5AC7AFDC
md5: a6df09cfae230c5cff4a2d25420ed4d1
name: A6DF09CFAE230C5CFF4A2D25420ED4D1.mlw
sha1: 12cec6e5a4ce98975bb60d58681984e34c29e659
sha256: 2584e989d0441977bd97181513a448c705f1fe0a8586b085c7b1aa8ebe29690f
sha512: 09d6fd173a7b190b62f922ff67ca9971dccd835bf126825ac8dd34772758b97c7f5e65850dbf0db849b058026be2ea828efa1f91073477c238eaaa0fb0537966
ssdeep: 12288:K6ZYPldQh7jh+QXcblglVE7DQmiPQZb3J8M99Ct+:Vslujh+cEGlVmePQpZ8M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Kibosoft Corp. 2001-2006
InternalName: SQLTools
FileVersion: 1.0.0.0
CompanyName: www.1285.net
LegalTrademarks: www.1285.net
Comments: SQLx7efcx5408x5229x7528x5de5x5177
ProductName: SQLx7efcx5408x5229x7528x5de5x5177
ProductVersion: 1.0.0.0
FileDescription: SQLx7efcx5408x5229x7528x5de5x5177
OriginalFilename: SQLTools
Translation: 0x0804 0x03a8

Jacard.147948 also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicHacktool.Win32.SqlTool.3!c
DrWebTool.Sqlhack
CynetMalicious (score: 85)
CMCGeneric.Win32.a6df09cfae!MD
ALYacGen:Variant.Jacard.147948
CylanceUnsafe
ZillyaTool.SqlTool.Win32.1
SangforTrojan.Win32.Lodap.rts
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.fae230
CyrenW32/Trojan.ILFH-4252
SymantecHacktool.SQLck
ESET-NOD32Win32/HackTool.SqlTool.B
AvastFileRepMalware [PUP]
ClamAVWin.Trojan.Sqltool-6
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Jacard.147948
NANO-AntivirusRiskware.Win32.SqlTool.hsqi
MicroWorld-eScanGen:Variant.Jacard.147948
TencentHackTool.Win32.Sql.ttk
Ad-AwareGen:Variant.Jacard.147948
ComodoTrojWare.Win32.HackTool.SqlTool.~dy01@1xyy7r
F-SecurePrivacyRisk.SPR/Tools.SqlTool
BitDefenderThetaAI:Packer.E05C390219
VIPRETrojan.Win32.Generic!BT
TrendMicroHKTL_SQLEXEC.C
McAfee-GW-EditionHTool-SQLExec
FireEyeGen:Variant.Jacard.147948
EmsisoftGen:Variant.Jacard.147948 (B)
WebrootW32.Malware.Gen
AviraSPR/Tools.SqlTool.B
eGambitTrojan.Generic
Antiy-AVLHackTool/Win32.SqlTool
KingsoftWin32.Hack.SqlTool.b.(kcloud)
MicrosoftTrojan:Win32/Lodap!rts
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Jacard.D241EC
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Jacard.147948
McAfeeHTool-SQLExec
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1004
PandaHackTool/Scansql.C
TrendMicro-HouseCallHKTL_SQLEXEC.C
RisingHack.SQLTool.a (CLOUD)
YandexTrojan.GenAsa!iqdmgJ6aKVk
IkarusBackdoor.Win32.Hupigon
MaxSecureTrojan.Malware.19137.susgen
FortinetRiskware/SqlTool
AVGFileRepMalware [PUP]

How to remove Jacard.147948?

Jacard.147948 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment