Worm

Worm:VBS/Jenxcus.C!rfn removal guide

Malware Removal

The Worm:VBS/Jenxcus.C!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:VBS/Jenxcus.C!rfn virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A wscript.exe process commonly used in script or document file downloaders initiated network activity
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

Related domains:

utcsvc.linkpc.net

How to determine Worm:VBS/Jenxcus.C!rfn?


File Info:

crc32: 5D2FB67B
md5: bb294c474d61c24a443a05e224d05b85
name: BB294C474D61C24A443A05E224D05B85.mlw
sha1: 0d0490923d0804bf3a9f87b9b5c0ab13955053e5
sha256: 2804df401fc26b4abdf5ccc7af8abb4fcac5ae9409868261ad1ebe714b799ff8
sha512: d6e3d0bad3787e5aa168708f027c88c623bc26995b66a913bc10a9f5833b31a6875e8aa90f23b58eae47d76d04665bc126c84e411d6c30e930e0b28927efd2b3
ssdeep: 6144:ajT5Zh17eWxoG/+ov/2OIQ4wW3OBsCeAWHTRRbK1xKTciONwmgIhxI:aRZ+IoG/n9IQxW3OBsey9RbK1xKAd+77
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Bernat
InternalName: UltraISO Portable
FileVersion: 0.0.0.0
CompanyName: PortableAppZ.blogspot.com
LegalTrademarks: PortableAppZ is a Trademark of Bernat
Comments: Allows UltraISO to be run from a removable drive. For additional details, visit http://portableappz.blogspot.com
ProductName: UltraISO Portable
ProductVersion: 0.0.0.0
FileDescription: UltraISO Portable
OriginalFilename: UltraISOPortable.exe
Translation: 0x0000 0x04e4

Worm:VBS/Jenxcus.C!rfn also known as:

K7AntiVirusTrojan ( 005115201 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader40.58092
CynetMalicious (score: 99)
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 005115201 )
SymantecTrojan.Gen.MBT
ESET-NOD32JS/Vjworm.F
APEXMalicious
AvastOther:Malware-gen [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.nbya
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.bb294c474d61c24a
MicrosoftWorm:VBS/Jenxcus.C!rfn
ZoneAlarmTrojan-Ransom.Win32.Blocker.nbya
McAfeeArtemis!BB294C474D61
MalwarebytesMalware.AI.232069753
PandaTrj/Genetic.gen
AVGOther:Malware-gen [Trj]

How to remove Worm:VBS/Jenxcus.C!rfn?

Worm:VBS/Jenxcus.C!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment