Malware

About “Johnnie.252820” infection

Malware Removal

The Johnnie.252820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.252820 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Johnnie.252820?


File Info:

name: 406BC4ACE39166BA6D2E.mlw
path: /opt/CAPEv2/storage/binaries/ce61678a1e8a8e564505f2c5dd7c418a0528b4ede5dd96b553b085b6affe177a
crc32: 4DBAA903
md5: 406bc4ace39166ba6d2e90ed7bbe277a
sha1: 9331fb8cc17e760877b4578c100b977ec2993525
sha256: ce61678a1e8a8e564505f2c5dd7c418a0528b4ede5dd96b553b085b6affe177a
sha512: dd23e5880c3328ac6cf485a035ef65bbe8dea2814e1aac390edda8abcf59396ba7ff6ed4b0d57402d0ca645609c06655503bddcc140da2ff4e73cc4dc3544a70
ssdeep: 1536:uXz5XTJcXSr4SJM4WUIL7RFsyTDPCIh9ZAEnhG1Qr8u:uXzZNcCr4shWj7RFsYCIiIhmQr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A493292374E4143AE33302367D687B3A97FFB93117E5869B937C48499BC24D4A94368B
sha3_384: 10ef9d5682ba8bfe775f69d2888df7cc386318aa9fd149fde14e389b5dd16d421057defeb69858cb1656f7498e745dc3
ep_bytes: e87d0b0000e93ffeffff57565533ff33
timestamp: 2016-08-04 22:54:13

Version Info:

0: [No Data]

Johnnie.252820 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Johnnie.252820
FireEyeGen:Variant.Johnnie.252820
ALYacGen:Variant.Johnnie.252820
SangforTrojan.Win32.Save.a
Cybereasonmalicious.ce3916
CyrenW32/S-0bb1eb58!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
BitDefenderGen:Variant.Johnnie.252820
VIPREGen:Variant.Johnnie.252820
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
EmsisoftGen:Variant.Johnnie.252820 (B)
GDataGen:Variant.Johnnie.252820
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Johnnie.D3DB94
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4923920
MAXmalware (ai score=83)
VBA32BScope.Trojan.Ymacco
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:NT8nMb2RavcycLbuGRitSQ)
IkarusTrojan.Win32.Ashify
MaxSecureTrojan.Malware.300983.susgen

How to remove Johnnie.252820?

Johnnie.252820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment