Worm

Worm.Win32.Juched.fhf removal

Malware Removal

The Worm.Win32.Juched.fhf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Juched.fhf virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Worm.Win32.Juched.fhf?


File Info:

name: 17E27344F45F3FAC710F.mlw
path: /opt/CAPEv2/storage/binaries/9b101701a37e344a665de9a77054cb31df214bd569f344e26d38c38c3e6bdb98
crc32: C8AAA6C6
md5: 17e27344f45f3fac710ffae8a7b4816e
sha1: fcac41a8a1be81ee3888b2c63bc7dbe4afeb8ab8
sha256: 9b101701a37e344a665de9a77054cb31df214bd569f344e26d38c38c3e6bdb98
sha512: e49aef3fab4b10402dcd902a0145f3e9d1af62f6b008e463344c9d929c05a2b969af08d368831baba151a6497e88da28f557744494a67f847843f5b1ed16fe0b
ssdeep: 1536:DXoYjfCB4mFVsIgvo3X4iZpTha5VlA8mD7aoL86yL7c:DXp3mFmIgvo4iZhha5rSaoL8627c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170554A20E600C07AECD241FAC6968BBAFD685E706B5550E3C3D1F9E9E7760E17A3144B
sha3_384: b77bdafd6c0a789876f6fdc95566189c1696a976d1b02e3c7b150ac726129c6cb7028f04cb1c986e755003561461e088
ep_bytes: 558bec6aff68f0784200681493400064
timestamp: 2012-11-23 02:49:25

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Worm.Win32.Juched.fhf also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.1103
FireEyeGeneric.mg.17e27344f45f3fac
CAT-QuickHealWorm.Ganelp.A6
SkyhighW32/Worm-FQU!17E27344F45F
McAfeeW32/Worm-FFR!17E27344F45F
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Juched.Win32.8820
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 001f4ea51 )
K7GWTrojan ( 001f4ea51 )
BitDefenderThetaGen:NN.ZexaF.36802.vD3@am!@tmeG
VirITTrojan.Win32.Agent_r.BOB
SymantecW32.Griptolo
ESET-NOD32a variant of Win32/Agent.SRG
APEXMalicious
TrendMicro-HouseCallWORM_GANELP.SMIA
ClamAVWin.Trojan.BankerSpy-1
KasperskyWorm.Win32.Juched.fhf
BitDefenderGen:Variant.Graftor.1103
NANO-AntivirusTrojan.Win32.Ursu.kcgpnr
TencentWorm.Win32.Juched.ha
EmsisoftGen:Variant.Graftor.1103 (B)
BaiduWin32.Trojan.Agent.dc
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen3.51589
VIPREGen:Variant.Graftor.1103
Trapminemalicious.moderate.ml.score
SophosW32/Ganelp-D
SentinelOneStatic AI – Malicious PE
JiangminWorm.Juched.z
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.Juched
XcitiumWorm.Win32.Juched.DGH@4nfk1p
ArcabitTrojan.Graftor.D44F
ZoneAlarmWorm.Win32.Juched.fhf
GDataWin32.Trojan.PSE.RJDMZ2
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.Juched.R641226
Acronissuspicious
VBA32BScope.Worm.Juched
ALYacGen:Variant.Graftor.1103
Cylanceunsafe
RisingTrojan.Agent!1.C135 (CLASSIC)
YandexTrojan.GenAsa!FgLooG3cvxI
IkarusTrojan.Win32.Webprefix
MaxSecureWorm.juched.pgy
FortinetW32/Agent.SRG!tr
PandaTrj/Genetic.gen
alibabacloudWorm:Win/Griptolo.360b116d

How to remove Worm.Win32.Juched.fhf?

Worm.Win32.Juched.fhf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment