Malware

Should I remove “Johnnie.180987”?

Malware Removal

The Johnnie.180987 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.180987 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

www.bing.com
ocsp.digicert.com
ajax.aspnetcdn.com
statics-marketingsites-eus-ms-com.akamaized.net
assets.onestore.ms
img-prod-cms-rt-microsoft-com.akamaized.net
sqm.msn.com
n777.no-ip.org

How to determine Johnnie.180987?


File Info:

crc32: 6ECE4CA2
md5: ef6b5eb4f7f551fecf4a9ab24d919c67
name: EF6B5EB4F7F551FECF4A9AB24D919C67.mlw
sha1: 8e49e60cb42c419fcc198bbbb42f6d4c6704fefa
sha256: aee826baa9cc115186896c52b151b468addd859f4e38f85d5df9322b11b34c95
sha512: 93199e88bcc000e7ab3cde77247229f199255e6e296d1773180d6b5f3311881167499778d9913b2524ecaff82eed5a12fb6edfa2b8c5687669a9edcc9b00a0b3
ssdeep: 24576:00pYlh2liW0XRyqBMaZevQC2GqgZLiKoMjVXezLFd/0gjZdSR:rKhWiPXRyqzZgiGqojMX0MZE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.180987 also known as:

K7AntiVirusTrojan ( 0055e3981 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.9735
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.180987
CylanceUnsafe
SangforTrojan.Win32.Blocker.usrg
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0055e3981 )
Cybereasonmalicious.4f7f55
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Kryptik.AMG
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jjkt
BitDefenderGen:Variant.Johnnie.180987
NANO-AntivirusTrojan.Win32.Bladabindi.eesrdr
MicroWorld-eScanGen:Variant.Johnnie.180987
TencentWin32.Trojan.Blocker.Anfv
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1122586
BitDefenderThetaGen:NN.ZemsilF.34758.hm0@aS!JJzd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.ef6b5eb4f7f551fe
EmsisoftGen:Variant.Johnnie.180987 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.agaw
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_96%
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Johnnie.D2C2FB
AegisLabTrojan.Win32.Generic.m119
ZoneAlarmTrojan-Ransom.Win32.Blocker.jjkt
GDataGen:Variant.Johnnie.180987
TACHYONRansom/W32.Blocker.1447441
McAfeeArtemis!EF6B5EB4F7F5
MAXmalware (ai score=99)
VBA32TrojanRansom.Blocker
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
YandexTrojan.Agent!cBBmzhRJ++U
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.HSF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Johnnie.180987?

Johnnie.180987 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment