jhzjpcc.vr

The file jhzjpcc.vr has been detected as malware by 28 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler.
MD5:
339c66f0916d3b0c2004a3b4c889994d

SHA-1:
0226b472e4f0a42504683ef58d1b7fdf9262dd2e

SHA-256:
5bf3157500765144264041920e15ab9bc51bf85421484ca496dceafc60f79afe

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/1/2025 8:08:44 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Worm/Win32.Conficker
2012.05.10

Avira AntiVirus
TR/Dropper.Gen
7.11.29.132

avast!
Win32:Malware-gen
2014.9-170315

AVG
Worm/Downadup
2018.0.2438

Bitdefender
Worm.Generic.267917
1.0.20.370

Clam AntiVirus
Worm.Kido-95
0.98/18155

Comodo Security
NetWorm.Win32.Kido.A
12271

Dr.Web
Win32.HLLW.Shadow.based
9.0.1.074

Emsisoft Anti-Malware
Net-Worm.Win32.Kido!IK
8.17.03.15.01

ESET NOD32
Win32/Conficker (variant)
11.7124

F-Prot
W32/Conficker!Generic
v6.4.6.5.141

F-Secure
Worm:W32/Downadup.gen!A
11.2017-15-03_4

G Data
Worm.Generic.267917
17.3.22

IKARUS anti.virus
Net-Worm.Win32.Kido
t3scan.1.1.118.0

K7 AntiVirus
Trojan
13.138.6839

Kaspersky
Net-Worm.Win32.Kido
14.0.0.-1313

McAfee
Artemis!339C66F0916D
5600.6094

Microsoft Security Essentials
Worm:Win32/Conficker.B
1.163.1557.0

Norman
W32/Conficker.FA
11.20170315

nProtect
Worm.Generic.267917
12.05.09.02

Panda Antivirus
W32/Conficker.C.worm
17.03.15.01

Quick Heal
Win32.Worm.Conficker.B.3
3.17.12.00

Sophos
Mal/Conficker-A
4.73 TP

Trend Micro House Call
WORM_DOWNAD.AD
7.2.74

Trend Micro
WORM_DOWNAD.AD
10.465.15

Vba32 AntiVirus
Worm.Win32.kido.89
3.12.16.4

VIPRE Antivirus
Worm.Win32.Downad.Gen
11897

ViRobot
Worm.Win32.Conficker.163026
2012.5.9.5082

File size:
89.8 KB (91,980 bytes)

Common path:
C:\Windows\System32\jhzjpcc.vr

File PE Metadata
Compilation timestamp:
11/17/2004 6:56:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

Entry address:
0x180D0

Entry point:
80, 7C, 24, 08, 01, 0F, 85, B9, 01, 00, 00, 60, BE, 00, 50, 00, 10, 8D, BE, 00, C0, FF, FF, 57, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.8122  (probably packed)

Code size:
80 KB (81,920 bytes)

Scheduled Task
Task name:
At1

Trigger:
Weekly (Runs weekly on Thursdays at 12:00 PM)


Remove jhzjpcc.vr - Powered by Reason Core Security