Categories: Malware

Johnnie.282121 information

The Johnnie.282121 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.282121 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Johnnie.282121?


File Info:

name: 475A57AE97A0C46622FE.mlwpath: /opt/CAPEv2/storage/binaries/9dc06846362e90e8aaa20a9ae754d877d6a3bda2f37184c8334f074b37deb0b0crc32: 2F39606Bmd5: 475a57ae97a0c46622fe2d83417b12a6sha1: 0a373cf0a5b71c24733b139fe2a2042b129a80e2sha256: 9dc06846362e90e8aaa20a9ae754d877d6a3bda2f37184c8334f074b37deb0b0sha512: 5c38cc4b5ce34439c47dfa123969e7d45262e62b372eb85aed782237be6a080d7831a5328627c57df7313aa2e67f91175232d814a0d2e09ff9ee6f73bfa104a2ssdeep: 6144:wY9W2aaP0sY5YCPhPX2G3FTIFdBNJOc5dZ96CB+Gs2Ty4OOivuZiLaV:H9W2aaJY5YqhPXNc5dB+Uy4OrDCtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T12B248C3AF4F28132C008D8770F07966ABC2E65538AB656E35E0E3D6A774D8C25D93DB1sha3_384: eb61cb0c13ca0874e39886649d2d2f2b8a86f4f37ee6b4a53b2091f42431c01e82dcee0014e633f97b24f05c6ef2fbdfep_bytes: e8d3190000e978feffff8bff558bec8btimestamp: 2012-05-15 01:42:00

Version Info:

0: [No Data]

Johnnie.282121 also known as:

Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Zbot.l!c
MicroWorld-eScan Gen:Variant.Johnnie.282121
FireEye Generic.mg.475a57ae97a0c466
ALYac Gen:Variant.Johnnie.282121
Cylance Unsafe
VIPRE Gen:Variant.Johnnie.282121
Sangfor Trojan.Win32.Crypt.atMYR
K7AntiVirus Trojan ( 0055e3991 )
K7GW Trojan ( 0055e3991 )
Cybereason malicious.e97a0c
Symantec Trojan.Zbot
Elastic malicious (high confidence)
ESET-NOD32 Win32/Spy.Zbot.YW
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Zbot-23153
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Johnnie.282121
NANO-Antivirus Trojan.Win32.Zbot.siowq
Avast Win32:Crypt-MYR [Trj]
Tencent Malware.Win32.Gencirc.114c2b1e
Ad-Aware Gen:Variant.Johnnie.282121
Emsisoft Gen:Variant.Johnnie.282121 (B)
Comodo Malware@#1t90kch3xpob1
DrWeb Trojan.PWS.Panda.547
Zillya Trojan.Zbot.Win32.62715
TrendMicro TSPY_ACYUF_BK082FEB.TOMC
McAfee-GW-Edition BehavesLike.Win32.Trojan.dh
Sophos Mal/Generic-S
Ikarus Trojan-PWS.Win32.Zbot
GData Gen:Variant.Johnnie.282121
Jiangmin Trojan/Jorik.cqst
Webroot W32.Malware.Gen
Google Detected
Avira HEUR/AGEN.1224060
MAX malware (ai score=83)
Antiy-AVL Trojan/Generic.ASMalwS.31
Arcabit Trojan.Johnnie.D44E09
ViRobot Trojan.Win32.A.Zbot.57838
Microsoft Trojan:Win32/Bulta!rfn
Cynet Malicious (score: 100)
McAfee Artemis!475A57AE97A0
TACHYON Trojan-Spy/W32.ZBot.225808
VBA32 TrojanSpy.Zbot
TrendMicro-HouseCall TSPY_ACYUF_BK082FEB.TOMC
SentinelOne Static AI – Suspicious PE
Fortinet W32/Zbot.AT!tr
BitDefenderTheta Gen:NN.ZexaF.34592.nuZ@amcgzoli
AVG Win32:Crypt-MYR [Trj]
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_90% (W)

How to remove Johnnie.282121?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

1 month ago