Malware

About “Johnnie.267901” infection

Malware Removal

The Johnnie.267901 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.267901 virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Johnnie.267901?


File Info:

crc32: 995347A4
md5: c9d7d8c3721d5be17528121ffe4e956d
name: Tax-Payent-Challan.exe
sha1: 3105762c44bd9f26e8e041181ebbf5a5be98eac4
sha256: aa8657e7f9e329cc7ef879da818f7adc89ec948bb78322104ac23b4822719abd
sha512: e303a71966bc18a1823fdd3e16018bcc40b1430568b4f1f591cf762f729c779b17ea134515ff8fafd9abcf1cf2eb82cd06393e051472708bf2adc9c7a44df4aa
ssdeep: 12288:nRBZegfhFCC46A9jmP/uhu/yMS08CkntxYRm:4mhFCtfmP/UDMS08Ckn3L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 1
FileVersion: 1.00
CompanyName: 128techconsultinginc
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: 1.exe

Johnnie.267901 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.267901
FireEyeGeneric.mg.c9d7d8c3721d5be1
ALYacGen:Variant.Johnnie.267901
CylanceUnsafe
K7AntiVirusSpyware ( 0000d4291 )
BitDefenderGen:Variant.Johnnie.267901
K7GWSpyware ( 0000d4291 )
CrowdStrikewin/malicious_confidence_90% (D)
Invinceaheuristic
BitDefenderThetaGen:NN.ZevbaF.34152.Fm0@aujYLOhi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.KeyLogger.NJK
APEXMalicious
KasperskyTrojan.Win32.Agent.xaedxi
AlibabaTrojanSpy:Win32/KeyLogger.2517c9bc
TencentWin32.Trojan-spy.Keylogger.Tbsh
Ad-AwareGen:Variant.Johnnie.267901
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen10.3378
TrendMicroTSPY_VBKEYLOG.SM
FortinetW32/KeyLogger.NJK!tr
SentinelOneDFI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
ArcabitTrojan.Johnnie.D4167D
ZoneAlarmTrojan.Win32.Agent.xaedxi
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!C9D7D8C3721D
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTSPY_VBKEYLOG.SM
RisingSpyware.KeyLogger!8.12F (CLOUD)
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Johnnie.267901
Cybereasonmalicious.3721d5
Paloaltogeneric.ml
SophosMLML/PE-A

How to remove Johnnie.267901?

Johnnie.267901 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment