Worm

Should I remove “Worm.Win32.Juched.fkf”?

Malware Removal

The Worm.Win32.Juched.fkf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Juched.fkf virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings

How to determine Worm.Win32.Juched.fkf?


File Info:

name: 8BFEC0B623076D77D937.mlw
path: /opt/CAPEv2/storage/binaries/e48dae242ddaa29b6c14024577b89dc61741e7a3141e0af4542133a6bb185155
crc32: EDA81189
md5: 8bfec0b623076d77d9370241bccf7c6b
sha1: dc80c39b1375359e477aa0428ca6a844ef1f9c91
sha256: e48dae242ddaa29b6c14024577b89dc61741e7a3141e0af4542133a6bb185155
sha512: 0d228aa9519eb3af757ee22d087a3ffd33e25a979d092ea89825bac6f37a1caa79ace327e272eea1d598770a510e0c3c82896e8f723c4a2eb6a015248b0b3303
ssdeep: 3072:wfQgicdlGvILcU9KQ2BBAkJaPxnIolv8ha22XX/xs:2icdlG5WKQ2BjGxxspY/2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8349E20E301C06EE8E142FDC2E68B76B6AC5F305B1850E7D7E5399E57352EAB93054B
sha3_384: f5bcad9f79c314c218c56ade3018d78459decdfcb95efd74b39e276f3d41f225792c707c059eace7241e426ef4ce6ae2
ep_bytes: 558bec6aff68b07742006840a8400064
timestamp: 2000-05-12 08:57:05

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Worm.Win32.Juched.fkf also known as:

LionicWorm.Win32.Juched.lyjw
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.20270
MicroWorld-eScanTrojan.Generic.7604330
FireEyeGeneric.mg.8bfec0b623076d77
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Generic.7604330
MalwarebytesBackdoor.IRCBot
ZillyaTrojan.Agent.Win32.153411
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 002a8f0e1 )
AlibabaMalware:Win32/km_2e737a.None
K7GWTrojan ( 001f4ea51 )
Cybereasonmalicious.623076
BitDefenderThetaGen:NN.ZexaF.34114.py2@aCwZ2CoG
VirITTrojan.Win32.Agent3.XOI
CyrenW32/Agent.KI.gen!Eldorado
SymantecW32.Griptolo
ESET-NOD32a variant of Win32/Agent.SRG
TrendMicro-HouseCallWORM_GANELP.SMIA
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyWorm.Win32.Juched.fkf
BitDefenderTrojan.Generic.7604330
NANO-AntivirusTrojan.Win32.Juched.dfacwp
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
AvastWin32:Dropper-GHV [Drp]
TencentTrojan.Win32.FakeFolder.bba
Ad-AwareTrojan.Generic.7604330
EmsisoftTrojan.Generic.7604330 (B)
ComodoWorm.Win32.Jushed.KA@4cysvx
BaiduWin32.Trojan.Agent.dc
VIPRETrojan.Win32.Autorun.BRF (v)
TrendMicroWORM_GANELP.SMIA
McAfee-GW-EditionBehavesLike.Win32.Autorun.dt
SophosML/PE-A + W32/Ganelp-A
IkarusTrojan.Win32.Webprefix
JiangminTrojan/Generic.acomf
MaxSecureWorm.Juched.dho
AviraTR/Spy.Agent.586689
Antiy-AVLTrojan/Generic.ASMalwS.11177
KingsoftWin32.Heur.KVM007.a.(kcloud)
GridinsoftRansom.Win32.Gen.sa
MicrosoftWorm:Win32/Ganelp.E
ViRobotWorm.Win32.Juched.209429
GDataWin32.Trojan.PSE.12MA8NB
AhnLab-V3Trojan/Win32.Npkon.R18258
Acronissuspicious
McAfeeW32/Autorun.worm.aacd
MAXmalware (ai score=83)
VBA32Trojan.Fuery
APEXMalicious
RisingTrojan.Agent!1.C135 (CLASSIC)
YandexTrojan.GenAsa!ceN4aAluftc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.SRG!tr
AVGWin32:Dropper-GHV [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.Juched.fkf?

Worm.Win32.Juched.fkf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment