Malware

GenScript.JVI removal tips

Malware Removal

The GenScript.JVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenScript.JVI virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

How to determine GenScript.JVI?


File Info:

crc32: 7A271722
md5: 3b61a9abfed587aa4fa860784c4e61e2
name: upload_file
sha1: 9eac05b7db84ebf6b39edf0655f6dde6f00cc2f6
sha256: 3588dcc8e075b8785a87dc01e4f4a2d81920606e1946816ea2c481d6a4020cb5
sha512: 976fb256fb01c3cbf4f040e0d3019190baccdcd8e397ca54c047eaace1af1b786cd01e381bf273ad967f26d600d2e310ef49a9d44673b2ececa128d7841e8eb0
ssdeep: 12288:Go2aJZEy3/AdZOdvfXeGlbU6dRE1eK/KaV+JvT7AMXaJZ2TceV6CNaQXfrz+P:gajEa/AsfXeGlbldRpKCn7778wZrzM
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 20 11:18:58 2020, Security: 0

Version Info:

0: [No Data]

GenScript.JVI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34394991
FireEyeTrojan.GenericKD.34394991
CAT-QuickHealX97M.Downloader.38800
ALYacTrojan.GenericKD.34394991
SangforMalware
TrendMicroTROJ_FRS.0NA103HK20
BitDefenderThetaGen:NN.ZedlaF.34242.ty5@aSY3W2ci
CyrenPNG/Trojan.USCY-8
SymantecTrojan.Gen.MBT
ESET-NOD32GenScript.JVI
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.34394991
NANO-AntivirusTrojan.Win32.Redcap.hsqoli
ViRobotDOC.Z.Agent.928668.B
AegisLabTrojan.Script.Generic.4!c
TencentWin32.Trojan.Generic.Llhh
Ad-AwareTrojan.GenericKD.34394991
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
DrWebTrojan.DownLoader34.18684
InvinceaTroj/DocDl-AAGO
SophosTroj/DocDl-AAGO
IkarusTrojan.Office.Doc
AviraHEUR/Macro.Downloader.MRUZ.Gen
Antiy-AVLTrojan/Generic.Generic
MicrosoftTrojanDropper:O97M/GraceWire.ARJ!MTB
ArcabitTrojan.Generic.D20CD36F
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.34394991
TACHYONSuspicious/W97.NS.Gen
McAfeeW97M/Downloader.dds
MAXmalware (ai score=98)
VBA32Trojan.Downloader
ZonerProbably Heur.W97Call
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
SentinelOneDFI – Malicious OLE
FortinetW32/Dropper.GIF!tr
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove GenScript.JVI?

GenScript.JVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment