Malware

GenScript.JVU information

Malware Removal

The GenScript.JVU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenScript.JVU virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with suspicious strings

How to determine GenScript.JVU?


File Info:

crc32: 0B95E270
md5: 022d1dd7195107b0e82151ac2876a25f
name: upload_file
sha1: c7c5b9a14747bfa43779d8f14af8c2a9a895c212
sha256: c47a16433fd7806a8344a21c412a6a0584aed75f5f1da9580990bf021b8f1635
sha512: 141b776a5bdd942822b6e8431ece75fea5a20fea57fb1699ad29f7fb9be8621508a9e56a00782449ff58be6db5f3ca8e77cad71a59cf5262070cc7ba65f08348
ssdeep: 3072:S4PrXcuQuvpzm4bkiaMQgAlSKOgiWMYKTLwohj/:TDRv1m4bnQgISKOxWMpLwohj/
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Quia., Author: Climence Caron, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Aug 21 04:00:00 2020, Last Saved Time/Date: Fri Aug 21 04:00:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 20, Security: 0

Version Info:

0: [No Data]

GenScript.JVU also known as:

Elasticmalicious (high confidence)
DrWebExploit.Siggen2.25683
MicroWorld-eScanVB:Trojan.VBA.Agent.BGM
FireEyeVB:Trojan.VBA.Agent.BGM
CAT-QuickHealOLE.Emotet.38803
ALYacTrojan.Downloader.DOC.Gen
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
TrendMicroTrojan.W97M.POWLOAD.THHBDBO
CyrenW97M/Downldr.gen
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.THHBDBO
ClamAVDoc.Malware.Generic-9443669-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BGM
NANO-AntivirusTrojan.Script.Downloader.htfcpy
ViRobotDOC.Z.Agent.189672.C
RisingMalware.ObfusVBA@ML.99 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BGM
SophosTroj/DocDl-AAGZ
F-SecureMalware.W97M/Agent.0034911
InvinceaTroj/DocDl-AAGZ
EmsisoftTrojan-Downloader.Macro.Generic.AL (A)
GDataMacro.Trojan-Downloader.Agent.AUG
AviraW97M/Agent.0034911
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.jvu
ArcabitVB:Trojan.VBA.Agent.BGM
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
CynetMalicious (score: 85)
AhnLab-V3Downloader/MSOffice.Generic
McAfeeW97M/Downloader.ddv
ZonerProbably Heur.W97Obfuscated
ESET-NOD32GenScript.JVU
TencentHeur.Macro.Generic.h.d52948ef
IkarusTrojan-Downloader.VBA.Emotet
FortinetVBA/Agent.K!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1080

How to remove GenScript.JVU?

GenScript.JVU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment