Malware

GenScript.JUL malicious file

Malware Removal

The GenScript.JUL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenScript.JUL virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with suspicious strings

How to determine GenScript.JUL?


File Info:

crc32: BA9DAA12
md5: a6e55d390fe49592c55991bf3d37b563
name: upload_file
sha1: e7d6d7d3547106cb10a5c7cef2defadd9bef61e4
sha256: 900062f8aeceaf3e82d45dac919862627ce1ef5646e173c9194626c2bb7e698c
sha512: ef7dc80dd033b870f7ae25b6e21f274cab8773bc19c64584dce6791e915ca7a40c3339502cefbf410d678949aa5e4858eb21e0328ded0898db8f2345eebcf80c
ssdeep: 3072:14PrXcuQuvpzm4bkiaMQgAlSHd5exIPwvHje:CDRv1m4bnQgISHdkx0wvHje
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Fugit., Author: Lou Masson, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Aug 18 15:04:00 2020, Last Saved Time/Date: Tue Aug 18 15:04:00 2020, Number of Pages: 1, Number of Words: 2, Number of Characters: 18, Security: 0

Version Info:

0: [No Data]

GenScript.JUL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB:Trojan.VBA.Agent.BGK
FireEyeVB:Trojan.VBA.Agent.BGK
CAT-QuickHealOLE.Emotet.38784
McAfeeW97M/Downloader.ddv
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.F04IE00HJ20
AvastScript:SNH-gen [Trj]
ClamAVDoc.Downloader.Generic-9375099-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BGK
ViRobotDOC.Z.Agent.180962
AegisLabTrojan.MSWord.Generic.4!c
RisingMalware.ObfusVBA@ML.97 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BGK
ComodoTrojWare.Win32.Unclassified.gen@0
F-SecureMalware.W97M/Agent.3995119
DrWebExploit.Siggen2.23197
TrendMicroTROJ_GEN.F04IE00HJ20
SophosTroj/DocDl-AAGJ
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.3995119
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.jul
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitVB:Trojan.VBA.Agent.BGK
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AUK
CynetMalicious (score: 85)
AhnLab-V3Downloader/DOC.Emotet.S1072
ALYacTrojan.Downloader.DOC.Gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32GenScript.JUL
TencentHeur.Macro.Generic.h.81a867da
FortinetVBA/Agent.GC!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1085

How to remove GenScript.JUL?

GenScript.JUL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment