Malware

Should I remove “Jacard.157612”?

Malware Removal

The Jacard.157612 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.157612 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com

How to determine Jacard.157612?


File Info:

crc32: F98FCC29
md5: db4632700245c146b234cb3410a226a5
name: DB4632700245C146B234CB3410A226A5.mlw
sha1: 2829b1317165a4403aad3fe953ef039a512bce94
sha256: 6402ebc275941f0eb2a9c1ae37c1a81c405145ff64bb7cadea5927f7d264c79a
sha512: 2d37db738193ebaa034c4b549a7548c15c638d34d5f87d01dff948434df738e0425eae980e23c03ee3d8d88999e3c332cde71e1bb2ec2b3de3b22fa23b379e70
ssdeep: 768:aZ8qCyaXBwQr533wsBULTCUkE69ilthyv1kdzSMKlhjPkJcKyUN9K2jP8x:agyaXVAsBULT3lthyHLTkJyUNgx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Jacard.157612 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4091 )
DrWebTrojan.Winlock.302
CynetMalicious (score: 100)
ALYacGen:Variant.Jacard.157612
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8522
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/SMSer.ec32cd98
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.00245c
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.BQ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.SMSer.lr
BitDefenderGen:Variant.Jacard.157612
NANO-AntivirusTrojan.Win32.SMSer.dkyoe
MicroWorld-eScanGen:Variant.Jacard.157612
TencentWin32.Trojan.Smser.Wrzy
Ad-AwareGen:Variant.Jacard.157612
SophosMal/Generic-S
ComodoMalware@#yjlhqbr6mw2a
BitDefenderThetaAI:Packer.4BC24AD419
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.pm
FireEyeGeneric.mg.db4632700245c146
EmsisoftGen:Variant.Jacard.157612 (B)
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.22D8B6
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabWorm.Win32.Fearso.kYUv
ZoneAlarmTrojan-Ransom.Win32.SMSer.lr
GDataGen:Variant.Jacard.157612
Acronissuspicious
McAfeeArtemis!DB4632700245
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.SMSer
PandaTrj/StartPage.DAW
RisingRansom.SMSer!8.12BE (CLOUD)
YandexTrojan.GenAsa!GXaSdJ9b+6w
IkarusTrojan-Dropper.Delf
FortinetW32/Generic.AC.B8B9!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Jacard.157612?

Jacard.157612 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment