Malware

What is “Johnnie.244011”?

Malware Removal

The Johnnie.244011 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.244011 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ip.tool.chinaz.com

How to determine Johnnie.244011?


File Info:

crc32: 5823AA5E
md5: 44ac832c2b71b4874e544e2b04a72834
name: system.exe
sha1: 2a148098915e88586f92b8401b79fec1f9862779
sha256: 7dd4cc7bb02d99e24d7d3bb8d79aacecf4f7c1c1241ed7ab47bc739908267ee2
sha512: 3c9beca591ca3e090ec6d61ca6886ad7784f8d51d354194ded2b4d40ae31e42a65ff1730dffb65b3d65b23c8ccee151e687b854ed34d2387f154b1bfada0a299
ssdeep: 768:yMjpswjMstxhmHrCgJihPfpEDbj8nr7Mmrc/e:Vq+M2mH0Pffra
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.244011 also known as:

MicroWorld-eScanGen:Variant.Johnnie.244011
FireEyeGen:Variant.Johnnie.244011
McAfeeRDN/Generic Downloader.x
AegisLabTrojan.Win32.PsDownload.a!c
BitDefenderGen:Variant.Johnnie.244011
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R049C0WEA20
SymantecTrojan.Gen.MBT
AvastWin32:Malware-gen
GDataGen:Variant.Johnnie.244011
KasperskyTrojan-Downloader.Win32.PsDownload.haa
AlibabaTrojanDownloader:Win32/PsDownload.3eef8252
RisingDownloader.PsDownload!8.E547 (CLOUD)
Endgamemalicious (high confidence)
SophosGeneric PUA CK (PUA)
ComodoMalware@#nn00mbnmuzat
F-SecureTrojan.TR/Dldr.Agent.uwugg
DrWebTrojan.DownLoader33.39958
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftGen:Variant.Johnnie.244011 (B)
CyrenW32/Trojan.GJKE-8949
WebrootW32.Backdoor.Gen
AviraTR/Dldr.Agent.uwugg
Antiy-AVLTrojan[Downloader]/Win32.PsDownload
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Johnnie.D3B92B
ZoneAlarmTrojan-Downloader.Win32.PsDownload.haa
BitDefenderThetaGen:NN.ZexaF.34108.cuW@aWFUOepi
ALYacGen:Variant.Johnnie.244011
MAXmalware (ai score=85)
VBA32BScope.TrojanDownloader.PsDownload
PandaTrj/RnkBend.A
TrendMicro-HouseCallTROJ_GEN.R049C0WEA20
TencentWin32.Trojan-downloader.Psdownload.Pdcu
IkarusPUA.PCDefender
eGambitUnsafe.AI_Score_80%
FortinetRiskware/PsDownload
Ad-AwareGen:Variant.Johnnie.244011
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.8f5

How to remove Johnnie.244011?

Johnnie.244011 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment