Malware

How to remove “Johnnie.267901 (B)”?

Malware Removal

The Johnnie.267901 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.267901 (B) virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Johnnie.267901 (B)?


File Info:

crc32: AA0CA1D1
md5: 8386b787dfff37c3e7bcdcc03a0a7487
name: image.exe
sha1: c20d9e818f912fc4f47ed1e85718c6196b911801
sha256: 25f0420d3551985569fb57497301c7d2f691083d7318d28db5bab2e8a6a0bb85
sha512: aace70e1d3bd221fffdcfe8649df4e47807b5f2679032866acf31b41814623eab85b6930bb9e79c11d4f48edfb5670d9d9a98941106c06c67cd9bd22f5c64bd0
ssdeep: 12288:zRBZegfhFC546A9jmP/uhu/yMS08CkntxYRT:EmhFCyfmP/UDMS08Ckn3C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 1
FileVersion: 1.00
CompanyName: 128techconsultinginc
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: 1.exe

Johnnie.267901 (B) also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.3378
MicroWorld-eScanGen:Variant.Johnnie.267901
FireEyeGeneric.mg.8386b787dfff37c3
ALYacGen:Variant.Johnnie.267901
MalwarebytesTrojan.MalPack
K7AntiVirusSpyware ( 0000d4291 )
K7GWSpyware ( 0000d4291 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Johnnie.D4167D
Invinceaheuristic
BitDefenderThetaGen:NN.ZevbaF.34152.Fm0@aCoHsCei
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.KeyLogger.gen
BitDefenderGen:Variant.Johnnie.267901
RisingSpyware.KeyLogger!8.12F (TFE:dGZlOgRfYzHjwZVMRg)
Ad-AwareGen:Variant.Johnnie.267901
EmsisoftGen:Variant.Johnnie.267901 (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTSPY_VBKEYLOG.SM
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojanSpy.KeyLogger.niz
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmTrojan.Win32.Agent.xaeerp
GDataGen:Variant.Johnnie.267901
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!8386B787DFFF
ESET-NOD32a variant of Win32/Spy.KeyLogger.NJK
TrendMicro-HouseCallTSPY_VBKEYLOG.SM
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/KeyLogger.NJK!tr
SophosMLMal/Generic-S

How to remove Johnnie.267901 (B)?

Johnnie.267901 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment