Malware

Jacard.191841 removal tips

Malware Removal

The Jacard.191841 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.191841 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)

Related domains:

api.xp666.com
download.xp666.com

How to determine Jacard.191841?


File Info:

crc32: 250F61C4
md5: 007f80a6f8e6f7408240a11a3cecdd81
name: hcrlm2bdb_345737.exe
sha1: e26b90375aff7a8a778c5614f23054570e8140b3
sha256: 3fadf8373985c724055a1a663babd4dec39662ce0cf51da46ecb86f6ba5e0afd
sha512: 64aa145d4402e46cfe32801f5d6d88e4b2eaacaa737b4526eb83269223acc71ea59eed1b38985b9bd10ae147f2086dee4619dba80bd3e99ddc5db365a2edd543
ssdeep: 49152:5U6w0yXS5yNoSG3YeVGg/Ykhfbes+8EmHFVFYTdzcbWgdt:5tcSlGgQufbesganWgd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
InternalName: FastDownload.exe
FileVersion: 2.9.2.380
OriginalFilename: FastDownload.exe
ProductVersion: 2.9.2.321
Translation: 0x0804 0x03a8

Jacard.191841 also known as:

MicroWorld-eScanGen:Variant.Jacard.191841
FireEyeGeneric.mg.007f80a6f8e6f740
Qihoo-360Generic/HEUR/QVM05.1.DC98.Malware.Gen
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Jacard.191841
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Jacard.191841
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
RisingDownloader.Agent!8.B23 (TFE:5:AfORLkkOduK)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Jacard.191841 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.Agentb.glb
ArcabitTrojan.Jacard.D2ED61
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
MicrosoftPUA:Win32/Caypnamer.A!ml
AhnLab-V3Trojan/Win32.Wacatac.C4131127
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jacard.191841
MAXmalware (ai score=83)
Ad-AwareGen:Variant.Jacard.191841
ESET-NOD32a variant of Win32/Duote.A
IkarusTrojan.Win32.Duote
FortinetW32/Duote.A!tr
BitDefenderThetaGen:NN.ZelphiF.34138.kV0@aeNV8Doi
AVGWin32:TrojanX-gen [Trj]

How to remove Jacard.191841?

Jacard.191841 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment