Trojan

Trojan.Downloader.JUBZ removal guide

Malware Removal

The Trojan.Downloader.JUBZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JUBZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
liquidmiracle.top
ec2-176-34-154-135.eu-west-1.compute.amazonaws.com
a.tomx.xyz
www.bing.com

How to determine Trojan.Downloader.JUBZ?


File Info:

crc32: 7CE52372
md5: 95181aef9e16566a54be6b86249fb88f
name: 95181AEF9E16566A54BE6B86249FB88F.mlw
sha1: 8616e77e40382cec097ed5b0138050b09950878c
sha256: de31e82f0b23a61000f88ae92fbbf7afff5d02dbc2d9a26df4a7c18091db1107
sha512: c197dda8feddf6f59b90a83cdd8f3a1156c270d483f6eceed56eeb05ed86f871d5babe2514bfcb37bdb0cc7f98154bf3fb96f38e7ad7c981e0df7d765971cdce
ssdeep: 24576:uC62EjqGxna6OYierFh9IfpUOSXELRdKVYuRuQ5q3h3gS:GDjqEierFhdOx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: wergdfgh herjhj first.LegalCopyright
InternalName: hwtgerth fdghjyt first.InternalName
FileVersion: dhertjjtryjdtyjt rtjyh jrtuk first.FileVersion
CompanyName: vdfghhdtjtuk jhlu hery first.CompanyName
LegalTrademarks1: dfhcvbjh herth first.LegalTrademarks1
LegalTrademarks2: cvbnerth gwet first.LegalTrademarks2
ProductName: zxfge erg dftyh first.ProductName
ProductVersion: hrtju zdfg ghsrth first.ProductVersion
FileDescription: gwrthhdryjtyjytj tuik erth first.FileDescription
OriginalFilename: dg afdg gerth first.OriginalFilename
Translation: 0x0409 0x04e4

Trojan.Downloader.JUBZ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 005232c51 )
LionicAdware.Win32.TOVus.2!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2527
CynetMalicious (score: 100)
ALYacTrojan.Downloader.JUBZ
CylanceUnsafe
ZillyaAdware.TOVus.Win32.66
SangforTrojan.Win32.Downloader.J
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanDownloader:Win32/TOVus.19f1e654
K7GWTrojan-Downloader ( 005232c51 )
Cybereasonmalicious.f9e165
CyrenW32/S-3d06037d!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.IE
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:AdWare.Win32.TOVus.akzx
BitDefenderTrojan.Downloader.JUBZ
NANO-AntivirusTrojan.Win32.Tovkater.ewxezi
MicroWorld-eScanTrojan.Downloader.JUBZ
TencentMalware.Win32.Gencirc.10c88004
Ad-AwareTrojan.Downloader.JUBZ
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.GCP@7ln01b
BitDefenderThetaGen:NN.ZexaF.34170.VnNfaypB9Qji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FPDH!C2279C09F33B
FireEyeGeneric.mg.95181aef9e16566a
EmsisoftTrojan.Downloader.JUBZ (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.TOVus.fd
WebrootW32.Rogue.Gen
AviraTR/Dldr.Tovkater.wcbhv
Antiy-AVLTrojan/Generic.ASMalwS.23F6BC5
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Downloader.JUBZ
AhnLab-V3Trojan/Win32.Downloader.C2346000
McAfeeArtemis!95181AEF9E16
MAXmalware (ai score=100)
VBA32AdWare.TOVus
MalwarebytesMalware.AI.31909473
PandaTrj/CI.A
YandexTrojan.GenAsa!IfHHhlWz+uA
IkarusTrojan-Downloader.Win32.Tovkater
FortinetW32/Tovkater.IE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Downloader.JUBZ?

Trojan.Downloader.JUBZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment