Malware

Johnnie.189984 (B) removal guide

Malware Removal

The Johnnie.189984 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.189984 (B) virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Johnnie.189984 (B)?


File Info:

crc32: 5F6EA203
md5: 5a20c05ac69ac5baa00df2f5f0b535e3
name: 5A20C05AC69AC5BAA00DF2F5F0B535E3.mlw
sha1: 40c8bb3848348d62d53f9b003dd87525d0055d2f
sha256: 4c964aeeacdaff2efde035551e108b485b1c9a1a7f785fddf9d015a6f30d25b4
sha512: 1f80a67bf4f75c0903fb62e3a5f6222d87465117be546d00ce31fe6313e191e35ef875d54bdba280f6e332df398cb07d2b388db4e6de4c622c698c88991a0771
ssdeep: 48:6x3QWdg16PGUK0TEYd9vIdvWuJcNYDijTSqA6akHjAfKtzfloxlSIrFWSfbNtm:23PGUKDfdyCickHjAeDq8szNt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012
Assembly Version: 1.0.0.0
InternalName: TestApp.exe
FileVersion: 1.0.0.0
ProductName: TestApp
ProductVersion: 1.0.0.0
FileDescription: TestApp
OriginalFilename: TestApp.exe

Johnnie.189984 (B) also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojanRansom.MSIL
ALYacGen:Variant.Johnnie.189984
CylanceUnsafe
ZillyaTrojan.Proxy.Win32.60
SangforTrojan.Win32.Wacatac.B
AlibabaRansom:MSIL/Proxy.e8dc3450
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ac69ac
CyrenW32/Trojan.TCPQ-4916
SymantecML.Attribute.HighConfidence
AvastMSIL:Agent-VP [Trj]
KasperskyTrojan-Ransom.MSIL.Proxy.j
BitDefenderGen:Variant.Johnnie.189984
NANO-AntivirusTrojan.Win32.Ransom.ivllob
MicroWorld-eScanGen:Variant.Johnnie.189984
TencentMsil.Trojan.Proxy.Svhg
Ad-AwareGen:Variant.Johnnie.189984
BitDefenderThetaGen:NN.ZemsilF.34722.am0@auDUYhe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Proxy.R035C0WEK21
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Johnnie.189984
EmsisoftGen:Variant.Johnnie.189984 (B)
JiangminTrojan.MSIL.zpay
WebrootW32.Trojan.Gen
AviraTR/Proxy.gwmhd
Antiy-AVLTrojan/Generic.ASMalwS.2B672A
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Johnnie.D2E620
AegisLabTrojan.MSIL.Proxy.j!c
GDataGen:Variant.Johnnie.189984
McAfeeArtemis!5A20C05AC69A
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Proxy.R035C0WEK21
IkarusTrojan.Proxy
MaxSecureTrojan.Malware.9084499.susgen
FortinetW32/Proxy.J!tr
AVGMSIL:Agent-VP [Trj]

How to remove Johnnie.189984 (B)?

Johnnie.189984 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment