Adware

Adware.Johnnie.106 removal

Malware Removal

The Adware.Johnnie.106 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Johnnie.106 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Collects information about installed applications
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

w.nanweng.cn
cdn.zry97.com
www.winrar.com.cn
s95.cnzz.com
s4.cnzz.com
ocsp.globalsign.com
ocsp2.globalsign.com
z11.cnzz.com
c.cnzz.com
z4.cnzz.com

How to determine Adware.Johnnie.106?


File Info:

crc32: 1DD286EE
md5: eafae0b1d9bea98c0d9a7e0f2ebdfe61
name: C3A5C2A4C2A9C3A6C2ADC2A3t20C3A6C2B3C2A8C3A5C286C28CC3A6C29CC2BA314_8694.exe
sha1: f36a4a88915816bcb2c257f69c2c93fb9945de35
sha256: 35915324aaa050e1ed92794593d4d9d5435cb91e18f74e8f34d1d32189a35554
sha512: 19f5f8fe431422617b46c346a3fda734a5a36343e2403eea194698a049817fe58a9fa25b70a5e424fdf4d0f54e512d9770dbf39dff975fe164d267f5104cddd5
ssdeep: 24576:gLQn5dEYkNjhHSt6aqaeUWVJGRR4pf9cVYan1fZCpVepsduNdc:jyYk5huYoIsf1sdkdc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0511
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Adware.Johnnie.106 also known as:

MicroWorld-eScanGen:Variant.Adware.Johnnie.106
FireEyeGeneric.mg.eafae0b1d9bea98c
McAfeeArtemis!EAFAE0B1D9BE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 00510c5c1 )
BitDefenderGen:Variant.Adware.Johnnie.106
K7GWAdware ( 00510c5c1 )
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Adware.Johnnie.106
Kasperskynot-a-virus:Downloader.Win32.Agent.miqz
AlibabaDownloader:Win32/Qjwmonkey.eccad8be
Endgamemalicious (high confidence)
SophosGeneric PUA PD (PUA)
ComodoApplicUnwnt@#3621grfx4m4a4
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Adware.Johnnie.106 (B)
CyrenW32/Adware.MSQS-3724
AviraADWARE/AD.QjwMonkey.jxpvq
ArcabitTrojan.Adware.Johnnie.106
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.miqz
MicrosoftPUA:Win32/Qjwmonkey
VBA32BScope.TrojanDropper.Dapato
ALYacGen:Variant.Adware.Johnnie.106
MAXmalware (ai score=99)
Ad-AwareGen:Variant.Adware.Johnnie.106
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CEE20
RisingAdware.Downloader!1.BDCA (CLASSIC)
eGambitTrojan.Generic
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.121218.susgen

How to remove Adware.Johnnie.106?

Adware.Johnnie.106 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment