Malware

Win32:GenMalicious-JHS [Trj] information

Malware Removal

The Win32:GenMalicious-JHS [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMalicious-JHS [Trj] virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
qq283492708.f3322.net
3600hk.no-ip.org

How to determine Win32:GenMalicious-JHS [Trj]?


File Info:

crc32: 2FD9272F
md5: d8000baf50117c1ce0ef8517177fa295
name: cxgjh.exe
sha1: 0396f37954c57af38d88b9e44b7e4e0cbaf21020
sha256: de6ea3664ce32184f6954bd6a6e0d311320b5f6293f0a23913d135c89a1fcd2f
sha512: 1cc3510ee6c6713a5dacc347579066eddeef980b92d906587c9243b8e3aa52c22ce4518927e5e88c12e4d6ebd6871c628d3bc5ffbbe4f22cb3abd36080953803
ssdeep: 196608:5g1PsSWg1PsSXuAaBIwbzWY/0NdDN7k104tWVBFF2xPBH+aLIpQhXkAC0TY3fZBH:5g1PWg1PPwbyYQ7pP7HwXklZWK5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: adbrowser
FileVersion: 1, 0, 0, 9
CompanyName: Net.Soft Studio
PrivateBuild: 20120830.01
LegalTrademarks:
Comments:
ProductName: adbrowser
SpecialBuild:
ProductVersion: 1, 0, 0, 9
FileDescription: P2Px7ec8x7ed3x8005x8f85x52a9x6a21x5757
OriginalFilename: adbrowser.EXE
Translation: 0x0804 0x04b0

Win32:GenMalicious-JHS [Trj] also known as:

MicroWorld-eScanGen:Trojan.Malware.@l3@aaMFFoeb
CAT-QuickHealTrojan.Agent.20341
McAfeeGenericRXDF-LU!D8000BAF5011
CylanceUnsafe
ZillyaTrojan.Black.Win32.47197
K7AntiVirusTrojan ( 0040f7ad1 )
BitDefenderGen:Trojan.Malware.@l3@aaMFFoeb
K7GWTrojan ( 0040f7ad1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R015C0DCA20
BaiduWin32.Trojan.Farfli.bg
F-ProtW32/S-6ad53990!Eldorado
APEXMalicious
AvastWin32:GenMalicious-JHS [Trj]
ClamAVWin.Trojan.Zegost-7007928-0
GDataWin32.Trojan.Farfli.0L99QR
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Malex.9187646d
NANO-AntivirusTrojan.Win32.Agent.elhpas
AegisLabTrojan.Win32.Agent.lJwa
TencentMalware.Win32.Gencirc.10b753c9
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Malware.@l3@aaMFFoeb (B)
ComodoTrojWare.Win32.Kryptik.BPVQ@56xtf6
F-SecureBackdoor.BDS/Zegost.Gen
DrWebTrojan.DownLoader22.4913
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Detnat.vc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d8000baf50117c1c
SophosMal/Generic-S
IkarusBackdoor.Win32.Zegost
CyrenW32/S-6ad53990!Eldorado
JiangminTrojan.Generic.aeyth
AviraBDS/Zegost.Gen
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Malware.E8ABDA
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Malex.gen!E
AhnLab-V3Trojan/Win32.Generic.R97658
Acronissuspicious
VBA32BScope.Backdoor.Spy
ALYacGen:Trojan.Malware.@l3@aaMFFoeb
MAXmalware (ai score=81)
Ad-AwareGen:Trojan.Malware.@l3@aaMFFoeb
PandaTrj/CI.A
ZonerTrojan.Win32.52717
ESET-NOD32Win32/Farfli.CMX
TrendMicro-HouseCallTROJ_GEN.R015C0DCA20
RisingBackdoor.Farfli!1.B6C5 (CLOUD)
YandexTrojan.Agent!qzuHQUHYfdI
SentinelOneDFI – Malicious PE
FortinetW32/Farfli.DZ!tr
BitDefenderThetaGen:NN.ZexaF.34100.@l3@aaMFFoeb
AVGWin32:GenMalicious-JHS [Trj]
Cybereasonmalicious.f50117
Qihoo-360Generic/HEUR/QVM41.2.81ED.Malware.Gen

How to remove Win32:GenMalicious-JHS [Trj]?

Win32:GenMalicious-JHS [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment