Malware

Johnnie.266075 malicious file

Malware Removal

The Johnnie.266075 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.266075 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

Related domains:

down.fei163.com
stat.fei163.com
www.baidu.com
barbars.oss-cn-hangzhou.aliyuncs.com
ocsp.globalsign.com
ocsp2.globalsign.com
crl.globalsign.net
crl.globalsign.com

How to determine Johnnie.266075?


File Info:

crc32: E93B3F90
md5: 66dd4dfb1a6715194ce6f4f437bc2cb6
name: downloader101521.exe
sha1: 6860bf474d4436f96fedad22a281397daa22e1bb
sha256: 37a15a8f67fea92857537e2cfcac3337914bc634d3b70f8440f7fafffdbde604
sha512: 3c38487e2f6abd1927959f34d877c3621ed0dad76bb5e2e436dd4a2144438a8466ee47e19282e983679cf70dc220de673a4a518fc6d92734f284b62b392538e0
ssdeep: 3072:D9009fFQ8sR/5VSP2MJiJRYC02hEnCUkZwX2wgO/Fuo6nbZSn223ZYynPBU5LW5:D9DtQ8sp5UP26iJRYt2hEnCUkZwX2wg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.266075 also known as:

BkavW32.AIDetectVM.malware2
FireEyeGeneric.mg.66dd4dfb1a671519
Qihoo-360Win32/Trojan.691
McAfeeGenericRXLQ-RC!66DD4DFB1A67
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blamon.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Johnnie.266075
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
TrendMicroTROJ_GEN.R03BC0WH520
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 90)
KasperskyTrojan.Win32.Blamon.rgb
AlibabaTrojan:Win32/Blamon.29206cda
NANO-AntivirusTrojan.Win32.Blamon.hqdddv
MicroWorld-eScanGen:Variant.Johnnie.266075
RisingTrojan.Blamon!8.E8FB (CLOUD)
Ad-AwareGen:Variant.Johnnie.266075
F-SecureTrojan.TR/Blamon.ladbp
DrWebTrojan.Siggen9.64182
ZillyaTrojan.Blamon.Win32.1730
FortinetW32/Blamon.RGB!tr
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.DQGY-7735
JiangminTrojan.Blamon.ama
AviraTR/Blamon.ladbp
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Blamon
ArcabitTrojan.Johnnie.D40F5B
ViRobotTrojan.Win32.Z.Blamon.161280
ZoneAlarmTrojan.Win32.Blamon.rgb
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Blamon.C4176238
BitDefenderThetaGen:NN.ZexaF.34182.jyW@amZPTdhi
ALYacGen:Variant.Johnnie.266075
VBA32BScope.Adware.Presenoker
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.DNHIABB
TrendMicro-HouseCallTROJ_GEN.R03BC0WH520
TencentMalware.Win32.Gencirc.11aab67e
IkarusTrojan.Blamon
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Johnnie.266075
AVGWin32:Malware-gen
Cybereasonmalicious.74d443
AvastWin32:Malware-gen

How to remove Johnnie.266075?

Johnnie.266075 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment