Malware

Johnnie.127900 information

Malware Removal

The Johnnie.127900 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.127900 virus can do?

  • Executable code extraction
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Johnnie.127900?


File Info:

crc32: C3E7CBDA
md5: 549f0e3f86e172202cc58600517c2a13
name: 549F0E3F86E172202CC58600517C2A13.mlw
sha1: 9d0fd810162af4eb987c5c70cbb97ec92d38fc3e
sha256: a107d87e77c484761bba22f3de4b0652b3aec7e7ca08e74398f7d711f8155a87
sha512: ad8e7c116ade184f0a2e8b046cdea8e51ffa6fe1842b9c523cabaaae653815ad05a08e64fb799560f24513f52bdaef7eee3d8cc34071871c602202d96c30623c
ssdeep: 6144:ddjCT+AGd51orrYh+5FjgEtFKO0JD6ym023JJuCv:3jCT+Aw5CPmsFjgoFKOsYuCv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Mining
FileVersion: 17.03.0006
CompanyName: 17.03 MB
ProductName: Micr0soft Cr4zy Sc1ipting
ProductVersion: 17.03.0006
OriginalFilename: Mining.exe
Translation: 0x0409 0x04b0

Johnnie.127900 also known as:

K7AntiVirusP2PWorm ( 004e4ae01 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.23735
ALYacGen:Variant.Johnnie.127900
MalwarebytesMalware.AI.4249294467
ZillyaTrojan.Agent.Win32.485624
CrowdStrikewin/malicious_confidence_100% (D)
K7GWP2PWorm ( 004e4ae01 )
Cybereasonmalicious.f86e17
ESET-NOD32a variant of Win32/AutoRun.VB.BIK
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.MSIL.Agent.fign
BitDefenderGen:Variant.Johnnie.127900
NANO-AntivirusTrojan.Win32.Drop.dffstz
MicroWorld-eScanGen:Variant.Johnnie.127900
TencentMalware.Win32.Gencirc.114b1671
Ad-AwareGen:Variant.Johnnie.127900
SophosML/PE-A
BitDefenderThetaAI:Packer.420788151F
VIPRETrojan.Win32.Generic!BT
TrendMicroPAK_Otorun8
FireEyeGeneric.mg.549f0e3f86e17220
EmsisoftGen:Variant.Johnnie.127900 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.pidx
AviraTR/Spy.36864.1988
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.BF62F9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Johnnie.127900
McAfeeGenericRXAA-AA!549F0E3F86E1
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Agent
TrendMicro-HouseCallPAK_Otorun8
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexTrojan.MulDrop!t+8wsveZoCQ
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KeyLogger.OCIA!tr
AVGWin32:Malware-gen

How to remove Johnnie.127900?

Johnnie.127900 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment