Malware

Johnnie.130598 malicious file

Malware Removal

The Johnnie.130598 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.130598 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Johnnie.130598?


File Info:

crc32: 326A6609
md5: 8fa62e1b5f3142b865a13b46cd53f678
name: 8FA62E1B5F3142B865A13B46CD53F678.mlw
sha1: af0bfe6c7d07c32da12c06427ded806782020071
sha256: 216040d7fb5da813850ee8df5a9ebc4b5ee49f0b697c85ea64467280ca4a0281
sha512: 9217f91904bacaad33604c67a0a921e10d238187e9c7d86ee4f43ece3b728d56790043333902816fc47a7479723491f7618838d94d016b3c179b29a8cf73b460
ssdeep: 1536:bxgvxUg+EeGI97C4oswzCED0PPPXPPPP7Eb0EgrEEknp18ne:bxgveED0PPPXPPPP7EgrEE2pge
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: KSEHGFN.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: Yn3wgg
ProductVersion: 1.0.0.0
FileDescription: Yn3wgg
OriginalFilename: KSEHGFN.exe

Johnnie.130598 also known as:

K7AntiVirusTrojan ( 0052915c1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.28414
CynetMalicious (score: 99)
ALYacGen:Variant.Johnnie.130598
CylanceUnsafe
ZillyaTrojan.Agent.Win32.981478
SangforTrojan.Win32.Agent.gen
AlibabaTrojanBanker:MSIL/Kryptik.bd03bcc7
K7GWTrojan ( 0052915c1 )
Cybereasonmalicious.b5f314
CyrenW32/Kryptik.IS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NBN
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.Agent.gen
BitDefenderGen:Variant.Johnnie.130598
NANO-AntivirusTrojan.Win32.Banker1.fiebgd
MicroWorld-eScanGen:Variant.Johnnie.130598
TencentWin32.Trojan-banker.Agent.Efbi
Ad-AwareGen:Variant.Johnnie.130598
SophosMal/Generic-S
ComodoMalware@#27zynrcee3zbz
BitDefenderThetaGen:NN.ZemsilF.34294.fm0@aSM2rRk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8fa62e1b5f3142b8
EmsisoftGen:Variant.Johnnie.130598 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1130173
eGambitUnsafe.AI_Score_51%
Antiy-AVLTrojan/Generic.ASMalwS.28192B2
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Johnnie.D1FE26
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Johnnie.130598
AhnLab-V3Trojan/Win32.Skeeyah.C2764848
McAfeeArtemis!8FA62E1B5F31
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1729687055
PandaTrj/GdSda.A
YandexTrojan.Kryptik!OKadz0NWKIE
IkarusTrojan-Downloader.Banker
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.NBN!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Johnnie.130598?

Johnnie.130598 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment