Malware

Jacard.221344 removal tips

Malware Removal

The Jacard.221344 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.221344 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Sniffs keystrokes
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Jacard.221344?


File Info:

name: 3C22BDDEAA911818945C.mlw
path: /opt/CAPEv2/storage/binaries/00ce2157f53bbe0ed10e943d52044c7a7a6d38ee991575615ba7c23c286daa47
crc32: 12F99700
md5: 3c22bddeaa911818945c14c189182067
sha1: 1c008a5f39d38c366a31d962151d6a55dca9bff7
sha256: 00ce2157f53bbe0ed10e943d52044c7a7a6d38ee991575615ba7c23c286daa47
sha512: db2941903fca2b68b5288482a7951a1f5c15132897618c1f3e49561c17f7c2cc9dd4ef534ce7841e521f0020f782b04904a229434c41fe41e7b86300cdc9c46a
ssdeep: 12288:GtLXhKdkDwSmsGtww4FpH72bu5oygbtHYIZswAIGM:G/XM7sFpTwHYIiIB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DB4F121F5C0C432E1121A78DC0AE5F995396F60EE7D119377CD3E5CBA7A28A052D2EB
sha3_384: bee6371471e4031bf6a23debf2fa47a44ce9743009821314968f6806035e3fec1bc927d2da24e165ed9f2f8c26cfd526
ep_bytes: 558bec83c4f0b89c9a4100e8b8abfeff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: No Patch
FileDescription: No Patch v11.02 Installation
FileVersion: v11.02
LegalCopyright: No Patch
Translation: 0x0409 0x04e4

Jacard.221344 also known as:

BkavW32.AIDetect.malware2
DrWebBackDoor.Bifrost.19762
MicroWorld-eScanGen:Variant.Jacard.221344
FireEyeGen:Variant.Jacard.221344
ALYacGen:Variant.Jacard.221344
CylanceUnsafe
K7GWRiskware ( 0040f0f51 )
K7AntiVirusRiskware ( 0040f0f51 )
BitDefenderThetaAI:Packer.7689D11A21
ESET-NOD32a variant of Win32/Injector.ANDS
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Jacard.221344
NANO-AntivirusTrojan.Win32.Bifrost.dcbwce
AvastWin32:Epik-A [Drp]
EmsisoftGen:Variant.Jacard.221344 (B)
ComodoMalware@#2fse93t6iuqsx
McAfee-GW-EditionGenericRXCD-IK!30743C5C2ED6
AviraHEUR/AGEN.1217095
MAXmalware (ai score=86)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Jacard.221344
CynetMalicious (score: 100)
McAfeeArtemis!3C22BDDEAA91
VBA32Trojan.MulDrop
APEXMalicious
IkarusBackdoor.Win32.Bifrose
FortinetW32/Injector.XLE
AVGWin32:Epik-A [Drp]
Cybereasonmalicious.eaa911
PandaTrj/CI.A

How to remove Jacard.221344?

Jacard.221344 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment