Malware

Jacard.166143 removal

Malware Removal

The Jacard.166143 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.166143 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

api.xp666.com
download.xp666.com

How to determine Jacard.166143?


File Info:

crc32: B2F5ECDB
md5: 5deb06f788a871be116d9c022330cfc4
name: nkhy2345_57808.exe
sha1: 07651c9c548372c1257200342b1dd493d1b86b8b
sha256: a7a148a01cdeba55da650e73f034488c1d952fbf863e7f60724516255a00d8ec
sha512: 414e973eb6c63d451af80ad8013b92babc6749c7e4f2b39adbfdba52e0029ed34804931c6f3f26838e6ab2019985d40609fe1f6161987b58e8daa66df4ea1872
ssdeep: 24576:89Cimr+sO6erf7FcJOJGwc6mxKnCGxPBSR8dvA9T:ViTsLeThcJscmdK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.9.0.224
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.9.0.210
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownload.exe
Translation: 0x0804 0x03a8

Jacard.166143 also known as:

MicroWorld-eScanGen:Variant.Jacard.166143
FireEyeGen:Variant.Jacard.166143
Qihoo-360Win32/Trojan.fc8
McAfeeArtemis!5DEB06F788A8
CylanceUnsafe
AegisLabTrojan.Win32.Jacard.4!c
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Jacard.166143
K7GWTrojan ( 0055e4261 )
Cybereasonmalicious.c54837
TrendMicroTrojan.Win32.WACATAC.THCOIBO
CyrenW32/Trojan.ITFX-8753
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Jacard.166143
RisingTrojan.Duote!8.11613 (CLOUD)
Ad-AwareGen:Variant.Jacard.166143
SophosMal/Generic-S
ComodoMalware@#15t6biiraqt94
F-SecureTrojan.TR/RedCap.jfgrx
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Jacard.166143 (B)
IkarusTrojan.Win32.Duote
AviraTR/RedCap.jfgrx
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Jacard.D288FF
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34100.bnKfau6Zyhni
ALYacGen:Variant.Jacard.166143
MAXmalware (ai score=99)
VBA32TScope.Trojan.Delf
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Duote.A
TrendMicro-HouseCallTROJ_GEN.R020H0CC920
YandexTrojan.Duote!
SentinelOneDFI – Malicious PE
FortinetW32/Doute.A!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Jacard.166143?

Jacard.166143 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment