jusched.exe

Java Platform SE Auto Updater

Oracle Corporation

The executable jusched.exe, “Java Update Scheduler” has been detected as malware by 16 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SunJavaUpdateSched’. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Oracle Corporation

Product:
Java Platform SE Auto Updater

Description:
Java Update Scheduler

Version:
2.8.45.15

MD5:
ba2a054f02370892666b4869ed0d51f6

SHA-1:
80f380363b029012f7551f8a695e031665b24c9a

SHA-256:
5eb2bfb2130b3f5a90622c33b73e9975d0d5c84237eff184cf1aea3ed177e635

Scanner detections:
16 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/7/2024 8:43:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5691347

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:SaliCode
160118-1

AVG
Win32/Sality
2015.0.4489

Boost by Reason
Optional.OracleCorporation.Startup
188838

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Virut.AI!Generic
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.4860.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4758034
46826

File size:
395 KB (404,528 bytes)

Product version:
2.8.45.15

Copyright:
Copyright © 2015

Original file name:
jusched.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\java\java update\jusched.exe

File PE Metadata
Compilation timestamp:
5/1/2015 2:15:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:47o5TUij33Rpra9UuieZUg9buAKkcXxgPmloa:42TUe33bruhic9iAKkcOmloa

Entry address:
0x23057

Entry point:
F6, C5, DA, 85, C3, 41, 0F, BE, CA, 32, E6, 51, 56, F7, C1, A6, 2E, F9, E6, E8, 4B, 00, 00, 00, 88, CB, 1A, EE, 81, F5, A6, 0B, 00, 00, 0F, C8, 87, F0, 0F, CB, 8D, 15, 4F, F0, 04, 00, 12, E7, 81, EA, E7, E3, 04, 00, F6, DB, 8A, C3, 81, EA, BE, 94, 04, 00, 0F, B7, CF, 81, C2, BD, 94, 04, 00, 69, DD, AF, 38, E8, 05, 3B, D6, 74, 07, C6, C7, 33, 0F, CF, B4, A2, 40, 81, FA, 92, 01, 00, 00, 73, D3, 8D, 3D, 2A, 10, A9, C1, 0F, CB, 8D, 0D, 7D, B6, AA, 91, 81, F9, 07, 85, 00, 00, 70, 02, 11, F9, FE, CE, BE, 9A, 51...
 
[+]

Entropy:
6.8904

Code size:
224 KB (229,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SunJavaUpdateSched

Command:
"C:\Program Files\common files\java\java update\jusched.exe"


Remove jusched.exe - Powered by Reason Core Security