Worm

What is “Worm:VBS/Jenxcus.E!rfn”?

Malware Removal

The Worm:VBS/Jenxcus.E!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:VBS/Jenxcus.E!rfn virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:VBS/Jenxcus.E!rfn?


File Info:

name: 3834F1E8E0CDE13B3063.mlw
path: /opt/CAPEv2/storage/binaries/a362922bc542ee43727b24da915ecc0ec572057214f8b6ad9ec7a0ae2f44bfda
crc32: A15BBC11
md5: 3834f1e8e0cde13b3063116fba78ddbb
sha1: 1417b8e889912b8af4a81a516d9f3588375f134e
sha256: a362922bc542ee43727b24da915ecc0ec572057214f8b6ad9ec7a0ae2f44bfda
sha512: 42ca1436a4703b09e5307f5a2b15d20f7e5693a660760c36ffa062fab335d1eb962b6d6197c39c4762f3d19f46bce1e2096236c412dada740b35363e6a8d3ff2
ssdeep: 196608:I1ctjlt0OhRFE1qVUMh1Um7QzYOkAYB0aWAJHWEb5g3AlObUqm5XLdjbTeKySyNi:AoJRFsoum7OHaCou3AleFm5Zj+K3p492
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDD63309EAE38AB1E59E09331D51FF0EAC74AD5335068A39BFF2B3DDC9625623114B50
sha3_384: 5366fd470688cb2c8098458ebe865134786ae6d9dd1867a0afb40d0228db0decddaec1db61e7bd0e4e5529b7a3c702b4
ep_bytes: e8ce040000e98efeffff3b0dc8a14300
timestamp: 2018-09-30 18:01:44

Version Info:

CompanyName: ByClick
FileDescription:
FileVersion: 2.2.108
InternalName: YouTubeByClick-Setup
LegalCopyright: Copyright (C) 2019 ByClick
OriginalFileName: YouTubeByClick-Setup.exe
ProductName: YouTube By Click
ProductVersion: 2.2.108
Translation: 0x0409 0x04b0

Worm:VBS/Jenxcus.E!rfn also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scrami.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.41910463
FireEyeTrojan.GenericKD.41910463
McAfeeArtemis!3834F1E8E0CD
MalwarebytesMalware.AI.3938447770
SangforDownloader.Vbs.Scrami.Vrw8
K7AntiVirusTrojan ( 005566f91 )
AlibabaTrojanDownloader:Win32/Scrami.5f67b28e
K7GWTrojan ( 005566f91 )
Cybereasonmalicious.8e0cde
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Scrami.ads
BitDefenderTrojan.GenericKD.41910463
NANO-AntivirusTrojan.Win32.Vjworm.gukrtj
TencentWin32.Trojan.Scrami.Fflw
EmsisoftTrojan.GenericKD.41910463 (B)
F-SecureMalware.VBS/Dldr.Nemucod.gjdez
DrWebTrojan.DownLoader30.9672
VIPRETrojan.GenericKD.41910463
TrendMicroTrojan.JS.VJWORM.BV
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
GDataTrojan.GenericKD.41910463
AviraVBS/Dldr.Nemucod.gjdez
XcitiumMalware@#lvceify8ka3e
ArcabitTrojan.Generic.D27F80BF [many]
ZoneAlarmTrojan.Win32.Scrami.ads
MicrosoftWorm:VBS/Jenxcus.E!rfn
VBA32Trojan.Scrami
ALYacTrojan.GenericKD.32363713
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.JS.VJWORM.BV
IkarusWorm.JS.AutoRun
MaxSecureTrojan.Malware.74780328.susgen
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Worm:VBS/Jenxcus.E!rfn?

Worm:VBS/Jenxcus.E!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment