Trojan

Should I remove “Trojan.Win32.Runner.jms”?

Malware Removal

The Trojan.Win32.Runner.jms is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Runner.jms virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Authenticode signature is invalid
  • CAPE detected the Lu0Bot malware family
  • A script or command line contains a long continuous string indicative of obfuscation

How to determine Trojan.Win32.Runner.jms?


File Info:

name: 533A9AB04FFEDE9F01CB.mlw
path: /opt/CAPEv2/storage/binaries/858bafe27080124fc1560894b00cf8c0c672df0bd0a66dbd08cf28b4cf9e1ee5
crc32: 5A08452F
md5: 533a9ab04ffede9f01cbf923ed1b9972
sha1: 1099f403bc55f4db6276f13f50694668f1aa0f58
sha256: 858bafe27080124fc1560894b00cf8c0c672df0bd0a66dbd08cf28b4cf9e1ee5
sha512: 73bf23779f1541425c7f3ea2c9d25a9a979c253e6b8e07676f6e37ce3909996e4a96a6adc60df847817ba4db5e881e621a47256699d24688f11e8048d63252ec
ssdeep: 48:6Sr0QdisGNkn8F6xu/yzEavuc0TcgCVvuBS:P0Q9GNknJxu/ahEhGuA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C25174CF426758B2DD9F813004AB5F42B7BA10358676513117B040F653F1950AD3EA55
sha3_384: e518ae1d26318d1a68344a32d5718f9fa5e30674a9f1a196ded218413e7c8a0f6a1076cb10fe0ce180a3dd84671e1357
ep_bytes: b802010201e91a000000b804000000e8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Runner.jms also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48250866
FireEyeGeneric.mg.533a9ab04ffede9f
ALYacTrojan.GenericKD.48250866
CylanceUnsafe
SangforTrojan.Win32.Runner.jms
K7AntiVirusTrojan-Downloader ( 0057eacb1 )
K7GWTrojan-Downloader ( 0057eacb1 )
Cybereasonmalicious.3bc55f
CyrenW32/Runner.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FSG
APEXMalicious
KasperskyTrojan.Win32.Runner.jms
BitDefenderTrojan.GenericKD.48250866
AvastWin32:Trojan-gen
TencentWin32.Trojan.Runner.Stao
Ad-AwareTrojan.GenericKD.48250866
SophosMal/Generic-S
DrWebTrojan.DownLoader44.35953
ZillyaTrojan.Runner.Win32.5709
TrendMicroTROJ_FRS.VSNTB422
McAfee-GW-EditionRDN/MalGenrc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.48250866 (B)
IkarusTrojan-Downloader.Win32.Agent
GDataTrojan.GenericKD.48250866
JiangminTrojan.Runner.hp
WebrootW32.Trojan.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3523ABD
KingsoftWin32.Troj.Runner.j.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Runner.2560.J
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4950464
McAfeeRDN/MalGenrc
VBA32Trojan.Runner
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_FRS.VSNTB422
RisingDownloader.Agent!8.B23 (CLOUD)
YandexTrojan.DL.Agent!nEYhayDj1lQ
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Malware
FortinetW32/Agent.FSG!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.139758744.susgen

How to remove Trojan.Win32.Runner.jms?

Trojan.Win32.Runner.jms removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment