Threat Database Worms Worm:VBS/Jenxcus.A

Worm:VBS/Jenxcus.A

By ZulaZuza in Worms

Threat Scorecard

Ranking: 9,057
Threat Level: 50 % (Medium)
Infected Computers: 42,461
First Seen: May 24, 2013
Last Seen: May 4, 2024
OS(es) Affected: Windows

Worm:VBS/Jenxcus.A is a worm that may be used to carry out various online deceptive tactics. Worm:VBS/Jenxcus.A is a Visual Basic worm, a type of threat that has decreased in popularity in recent years. Nonetheless, this is not what occurs in Latin America, where threats like Worm:VBS/Jenxcus.A account for nearly a third of all threat infections. Using Worm:VBS/Jenxcus.A, third parties may take over the victim's computer, essentially controlling it from a remote location. Worm:VBS/Jenxcus.A may be used to install other threats on the victim's computer. Using Worm:VBS/Jenxcus.A, cybercrooks may track on your activity, gain access to your classified data, delete or copy your data and use your computer for their own negative activities.

Why Worm:VBS/Jenxcus.A Poses a Threat to Your Computer?

One of the most threatening aspects of Worm:VBS/Jenxcus.A is that Worm:VBS/Jenxcus.A can spread on its own. Worm:VBS/Jenxcus.A does this by copying itself to external drives and using the affected computer's email and social networking accounts to expose the victim's contacts to Worm:VBS/Jenxcus.A. Because of the severe threat posed by Worm:VBS/Jenxcus.A, malware researchers advise the immediate use of a reliable security program to remove Worm:VBS/Jenxcus.A and ensure that no other threat has been installed on the infected computer. Because of Worm:VBS/Jenxcus.A's propensity to spread on its own from the affected computer, measures should be taken to ascertain that computers in contact with the affected PC have not been exposed to Worm:VBS/Jenxcus.A, either directly or indirectly through a removable memory device.

Protecting Your Computer from Worm:VBS/Jenxcus.A

The best way to prevent Worm:VBS/Jenxcus.A attacks is to use a reliable security program that is fully updated. It is also indispensable to ensure that your computer's software and operating system are also fully updated, especially because threats may exploit outdated software to execute damaging code on the victim's computer. Making sure that your operating system's security settings are optimal can also prevent Worm:VBS/Jenxcus.A attacks, especially because it is possible to prevent Visual Basic from been executed by modifying your computer's settings appropriately to prevent these types of unsafe scripts from running automatically.

SpyHunter Detects & Remove Worm:VBS/Jenxcus.A

File System Details

Worm:VBS/Jenxcus.A may create the following file(s):
# File Name MD5 Detections
1. aucasuaamb..vbs d82c234492b1c7e9dda4c18bcd683eed 46
2. notepad.vbe 9800ac59db799ae7f06fedf11283d9a0 39
3. aiasfacoafiasksf.vbs 956b497b00ec65a69d104dc041d799ea 38
4. notepad.vbe 8410fb812404192b8b64e660b58cedf6 25
5. iexplore.vbs 331c9f7566deaf84bd55ca09d0daeead 21
6. SYSTEM~1.VBE d2b4afcee5cd0eff2f8544ea63e6fba8 19
7. syswow64.vbs 664559346bac3e4f8de6ccbf318e9bf7 18
8. x-men.exe ab8d1191478a9380a5db8fdb2b10fac1 17
9. aiasfacoafiasksf.vbs d4c97093eac3514d7c241d063f7f9c0f 12
10. iexplore.vbs 93b2b0816f06a142cb372257fce67634 9
11. systeme.vbs 671d85bfd0f31e2e981343c744f7445b 9
12. iexplore.vbs 628fc59d3478ea2d5c243be8f2eb6b58 7
13. iso.vbs 55d3cc7a0de85f29bd63775c173352b5 3
14. crypted.vbs 0d2c909d279af7e09743c374df95c18f 3
15. iexplore.vbs e2a425b0fa8d5d2aef9c5ccf511625a9 1
16. h.vbs 00a0669becd62d05cb263a92e39c266a 1
17. Updatea.vbs 8aa5dd6372ce56edf60898b60b8005c8 1
18. HELP.vbs ff0e9cc57bbe4b994c833c785cb650f7 1
19. Updatea.vbs 6cf2bab38bc7d62812196f5655fbb6a7 1
20. DragonBound.vbs 20507787a47b320465369c207d3d127c 1
21. mugen.vbs 78c43cab7cef0d339e5e8170799f03b3 1
22. help.vbs 454cbd2770981525a7343b8f7ec047f7 1
23. iexplore.vbs 313bc260a05d59a191a6cee001f7ddc6 1
24. iexplore.vbs bebca84e3bbd07a55faeff5a2bfeb5fe 1
25. %TEMP% and [startup folder]njq8.vbs
26. %TEMP% and [startup folder]Servieca.vbs
27. %TEMP% and [startup folder]\Serviecs.vbs
More files

Registry Details

Worm:VBS/Jenxcus.A may create the following registry entry or registry entries:
File name without path
lllllllll1349327881578033048firewall.vbs
Regexp file mask
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup\CSrss.exe
%ALLUSERSPROFILE%\tmp[RANDOM CHARACTERS].tmp.vbs
%APPDATA%\[RANDOM CHARACTERS]..vbe
%APPDATA%\cool.vbs
%APPDATA%\microsoft.vbs
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\[RANDOM CHARACTERS]..vbe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\cool.vbs
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\home.vbe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\njw0rm.exe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Systeme.exe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\tmp[RANDOM CHARACTERS].tmp.vbs
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WinUpdat.vbs
%APPDATA%\mugen.vbs
%APPDATA%\notepad\notepad.vbe
%APPDATA%\tmp[RANDOM CHARACTERS].tmp.vbs
%TEMP%\[RANDOM CHARACTERS]..vbe
%TEMP%\iTunesHelper.vbe
%TEMP%\Microsofts.vbs
%TEMP%\mugen.vbs
%TEMP%\njw0rm.exe
%TEMP%\WinUpdat.vbs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Serviecs.vbs" = "%Temp%\Serviecs.vbs"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[malware file name]" = "[malware folder and file name]"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "[malware file name]" = "[malware folder and file name]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Serviecs.vbs" = "%Temp%\Serviecs.vbs"

1 Comment

I could not find this worm in the registry after scanning the system. Is there still any chance for this threat to remain in my computer? Please help

Trending

Most Viewed

Loading...