Malware

Jacard.168942 malicious file

Malware Removal

The Jacard.168942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.168942 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
pbstat.haotukankan.com
news.7654.com

How to determine Jacard.168942?


File Info:

crc32: 1F68672A
md5: 78710b49fb7693859182ecc4bc293e91
name: mininewshtkk-1.exe
sha1: d791dacb4039ee0079162a3727b40b919d2c57e8
sha256: 5f5be81e79f6900263c47d179ca00e4f8d6bbaba7e2503021546abdca9a65b57
sha512: 427a3545b0714b8c34c6a692f5ca1161588d6491b24c151edeb245ffc6eede062242dfac0735fc212c82aa146ccd4981573acc3b27686acd7737b54fbb3abc9c
ssdeep: 12288:WdPhwaca6ySnWZKDl84ftDlkJYoSQLv62Hok:WdPeaQ8v4fNlkJ5LvDHok
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: xwView
FileVersion: 5.0.1.5
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 5.0.1.5
FileDescription: xwView
Translation: 0x0804 0x04e4

Jacard.168942 also known as:

MicroWorld-eScanGen:Variant.Jacard.168942
CAT-QuickHealTrojan.CoinMiner
McAfeeArtemis!78710B49FB76
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.KuaiZip.1!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Jacard.168942
K7GWAdware ( 0055bff71 )
K7AntiVirusAdware ( 0055bff71 )
ArcabitTrojan.Jacard.D293EE
TrendMicroTROJ_GEN.R020C0PL919
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/KuaiZip.W potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.KuaiZip.gen
AlibabaBackdoor:Win32/CryptInject.c0877e6a
NANO-AntivirusRiskware.Win32.Kuaizip.glumda
AvastWin32:Malware-gen
Endgamemalicious (moderate confidence)
EmsisoftGen:Variant.Jacard.168942 (B)
ComodoMalware@#1uh8cofc42wxf
F-SecureHeuristic.HEUR/AGEN.1044579
DrWebProgram.Kuaizip.5
MaxSecureTrojan.Malware.74620079.susgen
ZillyaTool.KuaiZip.Win32.8
McAfee-GW-EditionPUP-XHW-XZ
FortinetRiskware/KuaiZip
FireEyeGeneric.mg.78710b49fb769385
SophosGeneric PUA NH (PUA)
CyrenW32/Trojan.VEKF-0569
JiangminRiskTool.KuaiZip.gq
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1044579
MAXmalware (ai score=82)
Antiy-AVLRiskWare[RiskTool]/Win32.KuaiZip
MicrosoftTrojan:Win32/CryptInject!MSR
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.KuaiZip.gen
AhnLab-V3PUP/Win32.Installer.C3862351
ALYacGen:Variant.Jacard.168942
Ad-AwareGen:Variant.Jacard.168942
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R020C0PL919
RisingAdware.Agent!1.BF80 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_97%
GDataGen:Variant.Jacard.168942
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Jacard.168942?

Jacard.168942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment