Malware

What is “Johnnie.25691”?

Malware Removal

The Johnnie.25691 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.25691 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Johnnie.25691?


File Info:

crc32: EB5CF1DD
md5: 62074a201e06d964b7e51fbd453b18f0
name: 62074A201E06D964B7E51FBD453B18F0.mlw
sha1: 3e5645567c188fe26426553932aac7a4cfa1317e
sha256: 4a066b5be87f0f2617bec8947e460070ad8dfb70444858941c0fb47f631ecd10
sha512: 89c697d50b8c52b23d9a5dc1d1fcea47c1f253d17020fd3020e457b490483f4f9b361f26d1d88292284cc04b7b06b20578f3b29f8c19167e1eb3e313202f05b9
ssdeep: 192:/TQSUamwFU8US0v0yizVRgD3CepD1umQUsGjRrukEfT67uDUyC+/:/Tfmw+S0v0yizVRgDvpYmQAYkuDUyC+/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: js22163
FileVersion: 1.00
CompanyName: x5faex8f6fx4e2dx56fd
ProductName: x5de5x7a0b1
ProductVersion: 1.00
OriginalFilename: js22163.exe

Johnnie.25691 also known as:

K7AntiVirusTrojan-Downloader ( 005134d71 )
Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.20188
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agentb.S260559
ALYacGen:Variant.Johnnie.25691
CylanceUnsafe
SangforTrojan.Win32.Agentb.8
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 005134d71 )
Cybereasonmalicious.01e06d
CyrenW32/S-2e015159!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.VB.RDP
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Johnnie-9839209-0
KasperskyTrojan.Win32.Agentb.anqa
BitDefenderGen:Variant.Johnnie.25691
NANO-AntivirusTrojan.Win32.dmhwhq.eaqdun
MicroWorld-eScanGen:Variant.Johnnie.25691
TencentAdware.Win32.VB.amr
Ad-AwareGen:Variant.Johnnie.25691
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZevbaF.34266.bm1@aiCfJUib
McAfee-GW-EditionBehavesLike.Win32.VBObfus.mz
FireEyeGeneric.mg.62074a201e06d964
EmsisoftGen:Variant.Johnnie.25691 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.acm
WebrootW32.AGentb.anqa
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Win32.Agentb.anqa
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Johnnie.D645B
GDataGen:Variant.Johnnie.25691
TACHYONTrojan/W32.Agent.28690
AhnLab-V3Trojan/Win32.Agentb.R130529
McAfeeGenericRXBZ-MB!62074A201E06
MAXmalware (ai score=87)
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!+bFnzERZkP0
IkarusTrojan.Win32.Agentb
FortinetW32/Agentb.ANQA!tr
AVGWin32:Evo-gen [Susp]

How to remove Johnnie.25691?

Johnnie.25691 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment