Malware

Should I remove “Johnnie.282384 (B)”?

Malware Removal

The Johnnie.282384 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.282384 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
support.apple.com
help.twitter.com
ldrpeset.casa
www.intel.com
support.oracle.com

How to determine Johnnie.282384 (B)?


File Info:

crc32: 98C613AC
md5: 8cf0f95e281c43b013ee718d7b3ffbd0
name: upload_file
sha1: aec2ce0525eb4e3dd82caeb593461bf9e1d16d78
sha256: 7bbfd3cdb378e8b5b966dcd76b83f1c4ed9004db4843d4ea4aef3cece3e04a67
sha512: cfb403b89be16f58b9ccbf6b0d807a2bee6668a8ca513c3bbcfeff888748a3f7936fb8560317e5d971e4d661d7d5755a2878cd99775537c889cd685bd01a90aa
ssdeep: 3072:2105WHcpNwEd1XY2bsxiRpACbyR7gbFem5:rWHcpNfdxhwxKNem5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2018 Minutehave Corporation. All rights reserved.
InternalName: full.dll
FileVersion: 6.5.5.597
CompanyName: Minutehave
ProductName: Minutehave Reply fair
OriginalFilename: full.dll
Translation: 0x0409 0x04b0

Johnnie.282384 (B) also known as:

BkavW32.AIDetectVM.malware2
McAfeeArtemis!8CF0F95E281C
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005710db1 )
K7GWTrojan ( 005710db1 )
CrowdStrikewin/malicious_confidence_70% (D)
InvinceaMal/Generic-S
SymantecTrojan Horse
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.IcedID.gen
AlibabaTrojanBanker:Win32/IcedId.5da56c78
TencentWin32.Trojan-banker.Icedid.Efuu
EmsisoftGen:Variant.Johnnie.282384 (B)
ComodoMalware@#3b0yptfflcdnq
F-SecureTrojan.TR/AD.PhotoDlder.gcxhk
TrendMicroTrojan.Win32.WACATAC.THJADBO
McAfee-GW-EditionRDN/GenMlwB
FireEyeGeneric.mg.8cf0f95e281c43b0
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/AD.PhotoDlder.gcxhk
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/IcedId.AR!MTB
AhnLab-V3Trojan/Win32.Wacatac.R353146
ZoneAlarmHEUR:Trojan-Banker.Win32.IcedID.gen
GDataWin32.Trojan.Agent.S8NEA9
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Kryptik.HGSK
ALYacTrojan.IcedID.gen
MalwarebytesTrojan.IcedID
TrendMicro-HouseCallTrojan.Win32.WACATAC.THJADBO
RisingTrojan.Generic@ML.86 (RDML:WDk4+g6DeDdV9MtO/WPdyQ)
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.12162265.susgen
FortinetW32/PhotoDlder.RDOA!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Johnnie.282384 (B)?

Johnnie.282384 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment