Malware

Johnnie.255459 removal tips

Malware Removal

The Johnnie.255459 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.255459 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

Related domains:

mbfce24rgn65bx3g.we0sgd.com
mbfce24rgn65bx3g.y8lkjg5.net

How to determine Johnnie.255459?


File Info:

crc32: CA51DA1F
md5: 61a4a791e48d817f58ba15057708edfc
name: 61A4A791E48D817F58BA15057708EDFC.mlw
sha1: 916db7929744a73cbcd54894b4a8f905e19141d0
sha256: a25bd79fb1d44e78d9997e24b77042661d7abeb00734b0c49158d38e923db429
sha512: 9e93352db69bd177c246bc73643579727966dcb91e8c7c121188abf1e9f75b345a878abef1d040c4db8fd5909a8fd672de268611f64f24e31b8362dd45106559
ssdeep: 6144:jXk5hOqBlpBnJ2ukfJtxosXlaYeQ/9T0XXEHH0gDgJSDQeO:zk5hOqBlpBJ2ukh91aYx0XUn0r6QeO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9HWorks. All rights reserved.
InternalName: Clearerror Decisin
FileVersion: 5.5.6.5
CompanyName: HWorks
PrivateBuild: 5.5.6.5
LegalTrademarks: Copyright xa9HWorks. All rights reserved.
Comments: Lines Celk Anthropological Typeddataset 1950s
ProductName: Clearerror Decisin
ProductVersion: 5.5.6.5
FileDescription: Lines Celk Anthropological Typeddataset 1950s
OriginalFilename: Clearerror Decisin.exe
Translation: 0x0409 0x04b0

Johnnie.255459 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f78ba1 )
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.255459
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7641
SangforTrojan.Win32.Injector.GE
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004f78ba1 )
Cybereasonmalicious.1e48d8
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.NHQ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.SageCrypt.czi
BitDefenderGen:Variant.Johnnie.255459
NANO-AntivirusTrojan.Win32.SageCrypt.enonkv
MicroWorld-eScanGen:Variant.Johnnie.255459
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Johnnie.255459
SophosMal/Generic-S
ComodoMalware@#14797astr64e6
BitDefenderThetaGen:NN.ZexaF.34692.xq1@aWet6Vpi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-23
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.61a4a791e48d817f
EmsisoftGen:Variant.Johnnie.255459 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.SageCrypt.ge
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.sjwds
eGambitUnsafe.AI_Score_93%
MicrosoftRansom:Win32/Milicry!rfn
ArcabitTrojan.Johnnie.D3E5E3
AegisLabTrojan.Win32.SageCrypt.j!c
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.czi
GDataGen:Variant.Johnnie.255459
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeArtemis!61A4A791E48D
MAXmalware (ai score=100)
VBA32Hoax.SageCrypt
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallMal_Cerber-23
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.SageCrypt!gM/dBhyLwL8
IkarusTrojan-Spy.Remcos
FortinetW32/Filecoder.NHQ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Johnnie.255459?

Johnnie.255459 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment