Worm

Worm:Win32/Jenxcus removal instruction

Malware Removal

The Worm:Win32/Jenxcus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Jenxcus virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

e7.sytes.net

How to determine Worm:Win32/Jenxcus?


File Info:

crc32: 620D8606
md5: 241414ef29b72a713ea5a30776a3aedf
name: 241414EF29B72A713EA5A30776A3AEDF.mlw
sha1: 5dd0df04a15c8eedfcc260ba2d5dc5bb5cb936c3
sha256: e1dad142aa37e44375e249675a8e3afaf7c83e23c1f6cf87a1fc2f5f53cfcb62
sha512: 96678570fa532da2fb6f051ce0e0aaa4dacc58766a828d71d28bf6db4a6c4080ab63354aaf82e01b9ae9ba4c344c0745927fb2593512d3d97b40ea05db5191ae
ssdeep: 49152:ifWy4twtQoaizs4V1/lbG2M9MuUdheVRm1:ifWyWiw4VplbG2pdhe+1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2002-2014
Assembly Version: 4.5.0.0
InternalName: CeC.exe
FileVersion: 4.5.0.0
CompanyName: ATI Technologies Inc.
Comments: CCC application for all ACE Components
ProductName: Catalyst Control Center
ProductVersion: 4.5.0.0
FileDescription: Catalyst Control Center: Host application
OriginalFilename: CeC.exe
Translation: 0x0809 0x04b0

Worm:Win32/Jenxcus also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 700000111 )
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.AutoIT.112
CylanceUnsafe
AlibabaRansom:Win32/Blocker.1d24e688
K7GWTrojan ( 700000111 )
Cybereasonmalicious.f29b72
CyrenW32/Worm.TZOF-5562
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Autoit.NA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jfej
BitDefenderGen:Trojan.Heur.AutoIT.112
NANO-AntivirusTrojan.Win32.Blocker.ejpxgp
MicroWorld-eScanGen:Trojan.Heur.AutoIT.112
TencentWin32.Trojan.Blocker.Hnuq
Ad-AwareGen:Trojan.Heur.AutoIT.112
SophosMal/Generic-S
ComodoMalware@#3dws4cxuakatr
BitDefenderThetaAI:Packer.50A5A6511A
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Agent.tc
FireEyeGeneric.mg.241414ef29b72a71
EmsisoftGen:Trojan.Heur.AutoIT.112 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.FrauDrop.zpa
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1105054
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftWorm:Win32/Jenxcus
GDataGen:Trojan.Heur.AutoIT.112
AhnLab-V3Malware/Win32.Suspicious.C256863
McAfeeGenericR-JZT!241414EF29B7
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
PandaTrj/CI.A
RisingTrojan.Generic@ML.96 (RDML:J5r8e4caixGEJrZIz+3p0g)
IkarusWorm.Win32.AutoIt
FortinetW32/Autoit.NA!worm
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Worm:Win32/Jenxcus?

Worm:Win32/Jenxcus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment