Malware

Johnnie.245802 information

Malware Removal

The Johnnie.245802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.245802 virus can do?

  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Johnnie.245802?


File Info:

crc32: DBAEACEA
md5: ceedb9a43122b1a19088119608fa6833
name: CEEDB9A43122B1A19088119608FA6833.mlw
sha1: d7edd8e5049925587ec0f8555ce4df690837d8ba
sha256: a88de9eb1c6468eba86b27ce6838db7efc9a5f70c0d50cc11dd984fe7c01152c
sha512: 1d7e207b47b1beeb08f817fda57685516f3aa4871bc931ef998ba3866296e6fb1ce6f96a1824af56a5492890bb5dfd5bf981fdcab37c6af6a3e598ba820e0856
ssdeep: 3072:3qOopqcyOLdWylDN2LmWam2uYB4T0IhVvE3:3qucXpWkDulf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016 WinPlugins
InternalName: WinPluginsUpdate.exe
FileVersion: 12.0.2.6
CompanyName: WinPlugins
ProductName: WinPluginsUpdate
ProductVersion: 2.0.2.3
FileDescription: WinPluginsUpdate
OriginalFilename: WinPluginsUpdate.exe
Translation: 0x0409 0x04b0

Johnnie.245802 also known as:

K7AntiVirusRiskware ( 0040eff71 )
ALYacTrojan.Ransom.FileCryptor
CylanceUnsafe
AlibabaTrojan:Win32/Deshacop.05a46582
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.43122b
SymantecRansom.Cerber
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Deshacop.cwg
BitDefenderGen:Variant.Johnnie.245802
NANO-AntivirusTrojan.Win32.Deshacop.ekyjrb
MicroWorld-eScanGen:Variant.Johnnie.245802
TencentWin32.Trojan.Deshacop.Tdzp
Ad-AwareGen:Variant.Johnnie.245802
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.gy0@ayfzBvfi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.nh
FireEyeGeneric.mg.ceedb9a43122b1a1
EmsisoftGen:Variant.Johnnie.245802 (B)
WebrootW32.Trojan.GenKD
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Generic.ASMalwS.19DAC37
KingsoftWin32.Troj.Deshacop.c.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
GDataGen:Variant.Johnnie.245802
McAfeeGeneric.anx
MAXmalware (ai score=100)
VBA32Trojan.Deshacop
PandaTrj/GdSda.A
FortinetW32/Deshacop.CWG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Johnnie.245802?

Johnnie.245802 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment