Malware

What is “Jacard.198002”?

Malware Removal

The Jacard.198002 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.198002 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Jacard.198002?


File Info:

crc32: C89F1917
md5: 4473d05873903ce6bcf1e809fd3f8ded
name: 4473D05873903CE6BCF1E809FD3F8DED.mlw
sha1: 482464986480c3a4192e3abe95e4c9a8e30d36f9
sha256: c6f079c55a2f7f047869a789a1db55a6251a87dbca5f033f298360cbd1343dc8
sha512: e47d0a759e647e5363c9f8ddbc32cbcaf0e46effe0dd68030ac827faacd928fdf78efe1b3384af83c5c8246ceb03bf2ca18b3d3ed7314d66b4f2a273d04e41af
ssdeep: 6144:GOqa4QjT7EPpvFsrIDfRZ7HyImYVpIGAaailMalyFn:GOV4wT1wZpmPG9aqQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Jacard.198002 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Filecoder.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Fenc
CynetMalicious (score: 100)
ALYacGen:Variant.Jacard.198002
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.2
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.873903
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Filecoder.a
BitDefenderGen:Variant.Jacard.198002
NANO-AntivirusTrojan.Win32.Filecoder.ffwh
MicroWorld-eScanGen:Variant.Jacard.198002
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Jacard.198002
SophosW32/FileCod-A
ComodoMalware@#3j73lhc4l2g0y
BitDefenderThetaAI:Packer.670625811F
McAfee-GW-EditionW32/Filecoder.cmp
FireEyeGeneric.mg.4473d05873903ce6
EmsisoftGen:Variant.Jacard.198002 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Filecoder.a
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.DBFF71
MicrosoftTrojan:Win32/Filecoder
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Jacard.198002
AhnLab-V3Trojan/Win32.Filecoder.C302582
Acronissuspicious
McAfeeW32/Filecoder.cmp
MAXmalware (ai score=87)
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
RisingTrojan.Filecoder.a (CLASSIC)
YandexTrojan.GenAsa!fYJd99qMjL4
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HwUBEpsA

How to remove Jacard.198002?

Jacard.198002 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment