Malware

Jacard.67018 information

Malware Removal

The Jacard.67018 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.67018 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the NetWire malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Jacard.67018?


File Info:

name: E98D88A1C335032603C1.mlw
path: /opt/CAPEv2/storage/binaries/23f5947027b30a949f3e0b74f996586cff0873441a681b465c38525af466481c
crc32: C2DE5623
md5: e98d88a1c335032603c1f01b5122755c
sha1: c9f35ea5826e52ac5337ada7a33e2b5aacf296d1
sha256: 23f5947027b30a949f3e0b74f996586cff0873441a681b465c38525af466481c
sha512: ff44da385bc32af451bd4a33cc7858af93513234fef61ad0b716b9e540b3894432f24c0e26c9d482d40c8cf025e58b4849b78d9f86eba06e1715e02fd2ad12fd
ssdeep: 24576:MyZcwCZx3H0MuyLoPMx99Uj3haPj2BXPSYjb9MFo49oM8ugiErCUV3/+Gp:MyZc0peFo4PtgifUJ/Vp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10315AF22A1B14837C1B77B389C7F9764AC3BBE60393458862BF51C4C9F397913929297
sha3_384: 65d98598a15fe93942897ab33d7bd0e5b0e178f17994af5387076f5930a84773e78af92e8e80a9e15ed747d65ba86e79
ep_bytes: 558bec83c4f053b8449e4800e82bc5f7
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: http://www.henrypp.org
CompanyName: Henry++
FileDescription: simplewall
FileVersion: 1.6.5
InternalName: simplewall
LegalCopyright: (c) 2016, 2017 Henry++. All Rights Reserved.
OriginalFilename: simplewall.exe
ProductName: simplewall
ProductVersion: 1.6.5
Translation: 0x0409 0x04e4

Jacard.67018 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Jacard.67018
FireEyeGeneric.mg.e98d88a1c3350326
SkyhighBehavesLike.Win32.Generic.dc
ALYacGen:Variant.Jacard.67018
Cylanceunsafe
ZillyaTrojan.Waldek.Win32.5302
SangforSpyware.Win32.Weecnaw.A
K7AntiVirusTrojan ( 005159731 )
AlibabaTrojanSpy:Win32/Waldek.0f199bdb
K7GWTrojan ( 005159731 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.ED65BF6A18
VirITBackdoor.Win32.Wirenet.NI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Weecnaw.A
APEXMalicious
KasperskyTrojan.Win32.Waldek.zry
BitDefenderGen:Variant.Jacard.67018
NANO-AntivirusTrojan.Win32.Waldek.esivqs
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Waldek.Ftgl
EmsisoftGen:Variant.Jacard.67018 (B)
F-SecureHeuristic.HEUR/AGEN.1354795
DrWebBackDoor.Wirenet.346
VIPREGen:Variant.Jacard.67018
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
JiangminTrojan.Waldek.fya
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1354795
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.969
MicrosoftPUAAdvertising:Win32/LoadMoney
XcitiumMalware@#uw4kr1734tlq
ArcabitTrojan.Jacard.D105CA
ZoneAlarmTrojan.Win32.Waldek.zry
GDataGen:Variant.Jacard.67018
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Recam.C2116763
McAfeeGenericR-KHU!E98D88A1C335
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingSpyware.Recam!8.5E5 (TFE:5:vfkrRlzGspI)
YandexTrojanSpy.Recam!L3K2uF/OW0c
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FVPB!tr
AVGWin32:DangerousSig [Trj]
DeepInstinctMALICIOUS

How to remove Jacard.67018?

Jacard.67018 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment