Malware

Johnnie.21605 removal guide

Malware Removal

The Johnnie.21605 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.21605 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Johnnie.21605?


File Info:

crc32: EAE8A9B2
md5: 9c87a3b6bbb2cb4ab783fc0b0e3cbc04
name: sansprinmoki.exe
sha1: 9ef7273ba5ab1c26f6d1d55be90c56c7dd7685c5
sha256: 87ab1a05cd495a10e7439d1df663d2d15e8456988f9e46b1b3f3baf635fd01e7
sha512: 58b7ce9e60b3b2f97fbeaf141680e2adaa94693145b8a16505340efd465fcc06aa3e934f8cf22cda842d4f70da3057dc11231673d7f18c84b38f11fac389b5c0
ssdeep: 6144:B+kypXDQ/m7iWmqTT9JNP/ua3LEwrOBP0AAKr33ClMvdDhS7VVKB0:BCu/PN8d/UEKrCsoVi0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.21605 also known as:

MicroWorld-eScanGen:Variant.Johnnie.21605
CAT-QuickHealBackdoor.Agent
Qihoo-360Win32/Backdoor.18b
McAfeeTrojan-FMYP!9C87A3B6BBB2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f03711 )
BitDefenderGen:Variant.Johnnie.21605
K7GWTrojan ( 004f03711 )
Cybereasonmalicious.6bbb2c
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Johnnie.21605
KasperskyBackdoor.Win32.Agent.dovl
AlibabaBackdoor:Win32/Injector.54401217
NANO-AntivirusTrojan.Win32.Dwn.edfgcd
ViRobotTrojan.Win32.Z.Zusy.570880.S
RisingBackdoor.Agent!8.C5D (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Johnnie.21605 (B)
F-SecureHeuristic.HEUR/AGEN.1026161
DrWebTrojan.DownLoader14.15241
ZillyaTrojan.Injector.Win32.386421
TrendMicroTROJ_GEN.R002C0PAB20
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.9c87a3b6bbb2cb4a
SophosMal/Kovter-P
IkarusTrojan.Win32.Injector
CyrenW32/Trojan.ABZR-6141
JiangminBackdoor.DarkKomet.ekk
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1026161
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Johnnie.D5465
AegisLabTrojan.Win32.Agent.m!c
ZoneAlarmBackdoor.Win32.Agent.dovl
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Backdoor/Win32.Agent.C1980261
Acronissuspicious
VBA32Trojan.Fsysna
ALYacGen:Variant.Johnnie.21605
Ad-AwareGen:Variant.Johnnie.21605
PandaTrj/GdSda.A
ESET-NOD32Win32/Injector.CYZQ
TrendMicro-HouseCallTROJ_GEN.R002C0PAB20
TencentMalware.Win32.Gencirc.10b576b9
YandexBackdoor.Agent!n8f75petVhE
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.354440!tr
BitDefenderThetaGen:NN.ZexaF.34090.IqW@auJy12kO
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.9660339.susgen

How to remove Johnnie.21605?

Johnnie.21605 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment