Malware

How to remove “Johnnie.2339”?

Malware Removal

The Johnnie.2339 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.2339 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Johnnie.2339?


File Info:

crc32: 5541A188
md5: 3594215acbb1bcd736c0f2aec09b4b08
name: 3594215ACBB1BCD736C0F2AEC09B4B08.mlw
sha1: 504a12614c236f843bb60d259af963a8fd8691cf
sha256: 0f2047255104025ef7b90ef43a35a5097d166a3315d15782c09cb559f67c8686
sha512: 18dae9e974fdb32426d15c3932280685578a33bbe357f0818c2685bf38c3dd32af2fe7ed3a58ce588037d3c9f7422bb0d26628f564af67fa3207170570b3ef4a
ssdeep: 3072:VLXKHBjmM3Qx26qzOWtfHmqRRBLmmZc7vuuPk5vKRVq2EXJj:dLM3L6hWtnvqI6vu5gGV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: @2015
Assembly Version: 2.5.1.6
InternalName: war.exe
FileVersion: 9.1.3.23
CompanyName: Microsoft
LegalTrademarks: Microsoft (TM)
Comments: Microsoft Coprotion
ProductName: Microsoft
ProductVersion: 9.1.3.23
FileDescription: Microsoft
OriginalFilename: war.exe

Johnnie.2339 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.29118
CynetMalicious (score: 99)
CAT-QuickHealWorm.Rebhip.20156
ALYacGen:Variant.Johnnie.2339
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.acbb1b
CyrenW32/Trojan.RCCY-0370
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EDP
ZonerTrojan.Win32.48671
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-PSW.MSIL.Azorult.gen
BitDefenderGen:Variant.Johnnie.2339
NANO-AntivirusTrojan.Win32.Razy.hikrwa
MicroWorld-eScanGen:Variant.Johnnie.2339
TencentMalware.Win32.Gencirc.10b30c98
Ad-AwareGen:Variant.Johnnie.2339
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34058.kq3@aaSwH3d
McAfee-GW-EditionGenericRXAD-VW!3594215ACBB1
FireEyeGeneric.mg.3594215acbb1bcd7
EmsisoftGen:Variant.Johnnie.2339 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1125935
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.E008E5
MicrosoftBackdoor:Win32/Bladabindi!ml
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Johnnie.D923
SUPERAntiSpywareTrojan.Agent/Gen-MSFake[Less]
GDataGen:Variant.Johnnie.2339
AhnLab-V3Trojan/Win32.Injector.R159938
McAfeeGenericRXAD-VW!3594215ACBB1
MAXmalware (ai score=86)
VBA32Backdoor.DarkKomet
MalwarebytesBackdoor.Agent.NSM
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:rCFs7w4Eo8acF8dgsrg2Dw)
YandexTrojan.Injector!Z6iFt//4TdQ
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.HJH!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM03.0.2287.Malware.Gen

How to remove Johnnie.2339?

Johnnie.2339 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment