Malware

What is “Johnnie.282898”?

Malware Removal

The Johnnie.282898 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.282898 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Johnnie.282898?


File Info:

crc32: DD34B298
md5: 630d53c48a1cc4ae8429172e912fafbc
name: upload_file
sha1: b5cabe6d0deabbcc3f77454a61943bd17cb53a74
sha256: ddaa332ad58071117dd067fb2e1d941f40a275343075a8d51ae296aa73ab43f1
sha512: 251f2d208549b44291d108559cd8977f6ab51a9e89123089059718ee33130a20eed37204dd1494a82501aefe2a00fa1b8c6787dce032ea4c792cd4c29490656f
ssdeep: 12288:yhMOxcMygxQGkGr/MzzwnCAavul0dA91nNzAUiN:yhPmNGQerEz0nXavs7nNi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2017 Verb spell Corporation. All rights reserved.
InternalName: Hurry.dll
FileVersion: 5.0.3.788
CompanyName: Verb spell
Comments: www.thirddictionary.ru
ProductName: Verb spell Has sat
Edge: Hot
ProductVersion: 5.0.3.788
OriginalFilename: Hurry.dll
Translation: 0x0409 0x04b0

Johnnie.282898 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.282898
ALYacGen:Variant.Johnnie.282898
CylanceUnsafe
K7AntiVirusSpyware ( 005612b41 )
AlibabaTrojanSpy:Win32/Cridex.3c076b83
K7GWSpyware ( 005612b41 )
ArcabitTrojan.Johnnie.D45112
InvinceaMal/Generic-S
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
BitDefenderGen:Variant.Johnnie.282898
ViRobotTrojan.Win32.Z.Johnnie.402432
AegisLabTrojan.Win32.Cridex.7!c
TencentMalware.Win32.Gencirc.11b047a9
Ad-AwareGen:Variant.Johnnie.282898
EmsisoftGen:Variant.Johnnie.282898 (B)
F-SecureTrojan.TR/AD.ZLoader.njjti
DrWebTrojan.Inject4.3500
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJJ20
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Johnnie.282898
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
AviraTR/AD.ZLoader.njjti
MAXmalware (ai score=81)
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftTrojan:Win32/Zloader.AR!MTB
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataGen:Variant.Johnnie.282898
CynetMalicious (score: 85)
ESET-NOD32Win32/Spy.Zbot.ADI
McAfeeGenericRXAA-AA!630D53C48A1C
VBA32BScope.TrojanBanker.Cridex
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJJ20
RisingSpyware.Zbot!8.16B (TFE:5:CpYAZRuwGhJ)
FortinetW32/GenKryptik.EUJX!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Qihoo-360Win32/Trojan.8a8

How to remove Johnnie.282898?

Johnnie.282898 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment