Trojan

What is “Trojan:Win32/JackServn.A”?

Malware Removal

The Trojan:Win32/JackServn.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/JackServn.A virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/JackServn.A?


File Info:

name: 82AF91D814B2F10DA4FE.mlw
path: /opt/CAPEv2/storage/binaries/0721c327d191c9370f1dfcaf93badc2200d8728145f504af8259def2a40b67ff
crc32: D75322F0
md5: 82af91d814b2f10da4fe91fd05b42262
sha1: 7597943e78c3d306a65e99d92bf92695cc8e4476
sha256: 0721c327d191c9370f1dfcaf93badc2200d8728145f504af8259def2a40b67ff
sha512: 4b29c32d2f60053c9773a78b59f9bdfb83b4d9ea7658ff6863176cf09ac2e9fc55dcb373608594aa441df224b309ed992e748bfd8c73ec1b883a2897e4495d06
ssdeep: 98304:kwviR04mOU10tIhZFLOAkGkzdnEVEFoKG:kwXZjFLOyEFoKG
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T174F57D7AEEBC00E5D446D47AC8469A9ED3B37C613E30839B505167ABEF733914C29326
sha3_384: 59f5f4c519da7d2e318d4ccb1c23547ed143de525b0426d2a553d3b69437ce128dee61fcc55fabf5077cab9e2fc40ab2
ep_bytes: 4883ec28e87bb600004883c428e91afe
timestamp: 2015-01-09 05:51:37

Version Info:

FileVersion: 1.0.0.1
InternalName: ServiceDownLoader.exe
LegalCopyright: All rights reserved.
OriginalFilename: ServiceDownLoader.exe
ProductVersion: 1.0.0.1
Translation: 0x0412 0x03b5

Trojan:Win32/JackServn.A also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Mikey.139333
FireEyeGeneric.mg.82af91d814b2f10d
ALYacGen:Variant.Mikey.139333
ZillyaTrojan.Badur.Win64.2
Cybereasonmalicious.814b2f
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/JackServn.A
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.139333
AvastWin64:Malware-gen
TencentMalware.Win32.Gencirc.1149dbf7
EmsisoftGen:Variant.Mikey.139333 (B)
F-SecureTrojan.TR/Rogue.cxb
VIPREGen:Variant.Mikey.139333
GDataGen:Variant.Mikey.139333
JiangminTrojan.Generic.eagyi
AviraTR/Rogue.cxb
Antiy-AVLTrojan/Win32.Badur
ArcabitTrojan.Mikey.D22045
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/JackServn.A
GoogleDetected
AhnLab-V3Trojan/Win64.Downloader.C768270
MAXmalware (ai score=85)
PandaTrj/CI.A
RisingTrojan.JackServn!8.2B9 (TFE:5:B8yM1z1UdTP)
YandexTrojan.Badur!1H8DTUlqYSs
IkarusTrojan.Win32.Badur
MaxSecureTrojan.Malware.300983.susgen
AVGWin64:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/JackServn.A?

Trojan:Win32/JackServn.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment