Malware

About “Jacard.172189” infection

Malware Removal

The Jacard.172189 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.172189 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

api.xp666.com
download.xp666.com

How to determine Jacard.172189?


File Info:

crc32: 3A04540E
md5: df0081c3d9e6f03c0968fe60a260b647
name: qviewer2345_13467.exe
sha1: 19f4828d6db21a7553648b0755b55908c71a30e2
sha256: d3aee80c14ee71aa81cf6cd1b3548593ad8120dbca2f7c1609163ff0ea52441d
sha512: c44ac6b688c040ac1474da16d9ac457530c9a647b47ceee328a5f1d9b9c1eee34dd5e17606bccaba7ae490a69fabd63b6f66f398f39ac08c190c7ebbdb3fa92d
ssdeep: 24576:mvtOu7VosnAhRp+iNLpeVlpxoGDKBsCd:YhZUGiskBsCd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.9.0.227
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.9.0.210
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownload.exe
Translation: 0x0804 0x03a8

Jacard.172189 also known as:

MicroWorld-eScanGen:Variant.Jacard.172189
Qihoo-360Win32/Trojan.fc8
McAfeeArtemis!DF0081C3D9E6
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Jacard.172189
K7GWTrojan ( 0055e4261 )
Cybereasonmalicious.d6db21
BitDefenderThetaGen:NN.ZelphiF.34100.6mKfaSt2a3hi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CCA20
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Jacard.172189
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Duote!8.11613 (CLOUD)
Ad-AwareGen:Variant.Jacard.172189
SophosMal/Generic-S
F-SecureTrojan.TR/RedCap.eaimx
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.dc
SentinelOneDFI – Malicious PE
Trapminemalicious.moderate.ml.score
FireEyeGen:Variant.Jacard.172189
EmsisoftGen:Variant.Jacard.172189 (B)
APEXMalicious
AviraTR/RedCap.eaimx
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Jacard.D2A09D
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Occamy.C
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jacard.172189
MAXmalware (ai score=82)
ESET-NOD32a variant of Win32/Duote.A
IkarusTrojan.Win32.Duote
FortinetW32/Doute.A!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Jacard.172189?

Jacard.172189 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment