Malware

Johnnie.265044 removal guide

Malware Removal

The Johnnie.265044 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.265044 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
360sd.site

How to determine Johnnie.265044?


File Info:

crc32: D4C18724
md5: 411aa7035d23f850e20b71a37f7d94be
name: user2020071800.exe
sha1: 6cc975d532d06b063b425b255d1ca15c8c14f8b7
sha256: cf2345a4ebd5cc15f4c117b27481f5aaceaf92fd26a672a816970860e3a6b1b4
sha512: df0386da66a4175962793b73f14775df69bee3ef26e94ecacb876ce95c4ddbd2e781d03218a039c4ce4ab5a21db544a865b340b736d54751073a762cbf0d9b47
ssdeep: 24576:5p/hSztNSvXnzD2lHV4a/G9x1UhjU+EwhrrngwmsemZEqda7zm:z/hSpofPGHV477/bornT9xZddL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.265044 also known as:

MicroWorld-eScanGen:Variant.Johnnie.265044
FireEyeGeneric.mg.411aa7035d23f850
McAfeeArtemis!411AA7035D23
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Johnnie.265044
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Ramnit-CY
GDataGen:Variant.Johnnie.265044
KasperskyTrojan-Dropper.Win32.Dapato.qhlv
AegisLabTrojan.Win32.Dapato.b!c
TencentWin32.Trojan-dropper.Dapato.Oyoo
Ad-AwareGen:Variant.Johnnie.265044
EmsisoftGen:Variant.Johnnie.265044 (B)
IkarusTrojan.Win32.Gupboot
MAXmalware (ai score=88)
Endgamemalicious (high confidence)
ArcabitTrojan.Johnnie.D40B54
ZoneAlarmTrojan-Dropper.Win32.Dapato.qhlv
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.265044
PandaTrj/GdSda.A
RisingVirus.Ramnit!8.4 (CLOUD)
FortinetW32/Dapato.QHLV!tr
AVGWin32:Ramnit-CY
Cybereasonmalicious.532d06
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.09e

How to remove Johnnie.265044?

Johnnie.265044 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment