Malware

Jacard.83424 (B) malicious file

Malware Removal

The Jacard.83424 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Jacard.83424 (B) virus can do?

  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Indonesian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Attempts to block SafeBoot use by removing registry keys

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Jacard.83424 (B)?


File Info:

crc32: A8FACE76
md5: ccfd9553687541748391c1e1fb241640
name: CCFD9553687541748391C1E1FB241640.mlw
sha1: ab6921579fb2ae59b11f7562b0a4fe44583f6d48
sha256: df868f4bbce575967e41abed94ecc57896bb1315dc73007d7e1dedda7d428743
sha512: 42198f8594fa1cc7cf81a9a989556841c02e49f484849f968a83f5f5af94cdefbff9255852d5e413707f2249ce2bf6fe0ed6327ec17f524c098717c2e0a6b3ba
ssdeep: 3072:WwCVIZCFElyDUVfMgwGZRtxk2N3DBaKjZ6muJYtcHybp4ZZKD1:WwCVHfDEFwMtHcKtzIYtgM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 2001-2004 CaesarSOFT Inc.
InternalName:
FileVersion: 6.0.1.1255
CompanyName: CaesarSOFT
LegalTrademarks:
Comments: visit http://www.caesarsoft.com
ProductName: CyberBilling
ProductVersion: XP
FileDescription: CyberBilling Client
OriginalFilename: CyberClient
Translation: 0x0421 0x04e4

Jacard.83424 (B) also known as:

LionicAdware.Win32.UBar.lw4g
ALYacGen:Variant.Jacard.83424
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41314
AlibabaRansom:Win32/Blocker.1053ba39
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.hvmv
BitDefenderGen:Variant.Jacard.83424
NANO-AntivirusTrojan.Win32.Blocker.ellptu
MicroWorld-eScanGen:Variant.Jacard.83424
TencentWin32.Trojan.Blocker.Tdpt
Ad-AwareGen:Variant.Jacard.83424
SophosMal/Generic-S
BitDefenderThetaAI:Packer.F8A5216818
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGen:Variant.Jacard.83424
EmsisoftGen:Variant.Jacard.83424 (B)
JiangminTrojan.Blocker.clx
AviraTR/ATRAPS.Gen
MicrosoftTrojan:Win32/Occamy.B
GDataGen:Variant.Jacard.83424
AhnLab-V3Malware/Win32.Generic.C1594424
McAfeeArtemis!CCFD95536875
MAXmalware (ai score=100)
PandaTrj/CI.A
YandexTrojan.ATRAPS!eZjy0VcyoPg
FortinetW32/Blocker.HVMV!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Jacard.83424 (B)?

Jacard.83424 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment