Malware

Johnnie.256883 removal

Malware Removal

The Johnnie.256883 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.256883 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Johnnie.256883?


File Info:

name: A579B9FE1184C39C5F5E.mlw
path: /opt/CAPEv2/storage/binaries/e40bdd8ff9e6432008afd54d6d526049ac6bd925dadc2b5a38f78c96df950d1a
crc32: 1EB75E7D
md5: a579b9fe1184c39c5f5e3257f9a38b59
sha1: 49d9ac447d7f6493df0128201d8f9e84d391f17d
sha256: e40bdd8ff9e6432008afd54d6d526049ac6bd925dadc2b5a38f78c96df950d1a
sha512: 86c1dc2d5dadc1007b16233c979c0a4e9fc97c8ea20ffafc98c272e0d27244908282b3f5367e46453090c012b5b91478be5362582180544c0cca5e627e38c768
ssdeep: 24576:J6ey22Kjx63blAhcTWEzWd1sXbxjQsB8KeX:J6eyB30cTlTxE08VX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16B653811BB905028FCF316FA5AFE606D453CBAE00B6890C761C86AEE5A25BF17D31753
sha3_384: c31165b573c7bd9434a3fb80a0fa6c80e5768137eecad74edcca0bb79bac50b43d9cb3c22479fadd6d14da22136aadef
ep_bytes: e92c720600e967d90700e922c10200e9
timestamp: 2019-10-01 09:37:07

Version Info:

0: [No Data]

Johnnie.256883 also known as:

BkavW32.Common.48E95B4A
LionicTrojan.Win32.Shelma.W!c
MicroWorld-eScanGen:Variant.Johnnie.256883
ClamAVWin.Trojan.Indigo-8092276-0
FireEyeGeneric.mg.a579b9fe1184c39c
SkyhighGeneric trojan.ks
McAfeeGeneric .ks
Cylanceunsafe
ZillyaTrojan.Shelma.Win32.3459
SangforTrojan.Win32.Shelma.Vkw1
AlibabaTrojan:Win32/Shelma.8b778e34
ArcabitTrojan.Johnnie.D3EB73
BitDefenderThetaGen:NN.ZexaE.36680.xPW@aithjMni
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Shelma.apkd
BitDefenderGen:Variant.Johnnie.256883
AvastWin32:Trojan-gen
TencentWin32.Trojan.Shelma.Qsmw
EmsisoftGen:Variant.Johnnie.256883 (B)
F-SecureTrojan.TR/Shelma.cxwem
VIPREGen:Variant.Johnnie.256883
TrendMicroTrojan.Win32.INDIGODROP.YPAF-A
SophosMal/Generic-S
IkarusTrojan.Win32.Casdet
JiangminTrojan.Shelma.dow
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Shelma.cxwem
Antiy-AVLTrojan/Win32.Shelma
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojan:Win32/Casdet!rfn
ZoneAlarmTrojan.Win32.Shelma.apkd
GDataGen:Variant.Johnnie.256883
VaristW32/Agent.BVF.gen!Eldorado
ALYacTrojan.Agent.Swrort
MAXmalware (ai score=89)
VBA32BScope.Trojan.Shelma
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.INDIGODROP.YPAF-A
RisingTrojan.Generic@AI.100 (RDML:mX8PsxuDiWMPQVid+Xrf4w)
YandexTrojan.Shelma!1lndnH9Xw4A
SentinelOneStatic AI – Suspicious PE
FortinetW32/Shelma.APKD!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Johnnie.256883?

Johnnie.256883 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment