Malware

Should I remove “Johnnie.288192”?

Malware Removal

The Johnnie.288192 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.288192 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Johnnie.288192?


File Info:

name: E47DC227E294AC60FCE8.mlw
path: /opt/CAPEv2/storage/binaries/df8a7f759382e0c64c953ca2b2733af7f579083fc4fb40cefc6d2fd4db7a6e79
crc32: F37A0F91
md5: e47dc227e294ac60fce8731f8b461735
sha1: 9eccb3fe3bfb7c92bdc20af37025d8532ada8e09
sha256: df8a7f759382e0c64c953ca2b2733af7f579083fc4fb40cefc6d2fd4db7a6e79
sha512: d66b4af3b210084cbb80ec26ee7f7674e9cba02ef7aa49a7ab48e71934cabb3e5ab9b404ecb11bc367cc100b068b7e44bbc09144779a901a006835a2a6a5f605
ssdeep: 3072:tTFIwgjuwKCHdihbCepGvf+QbeMnwo2qGlswdmWGBttY3UJZ:tTfGuwKC9UpG33byo2+43U3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3F35D30FAA0C039F4B702F985F687ACB9297D715B3894CB63D5659A12346E9EC31393
sha3_384: fe470a56357735150563d4058bd92a14398d03c2c9d0408a6f5c9de098b9aa96b7d356aa7f737b599245bc4437782934
ep_bytes: 558bece838430000e8030000005dc3cc
timestamp: 2013-06-12 15:13:42

Version Info:

CompanyName: 益盟
FileDescription: 益盟信息
FileVersion: 1.2
InternalName: YmPlatform.exe
LegalCopyright: (C) 。保留所有权利。
OriginalFilename: YmPlatform.exe
ProductName: 操盘手主站通知
ProductVersion: 1.2
Translation: 0x0804 0x03a8

Johnnie.288192 also known as:

LionicTrojan.Win32.Agentb.4!c
DrWebTrojan.PWS.Gamania.41476
MicroWorld-eScanGen:Variant.Johnnie.288192
FireEyeGen:Variant.Johnnie.288192
ALYacGen:Variant.Johnnie.288192
CylanceUnsafe
ZillyaTrojan.Agentb.Win32.1052
AlibabaTrojanPSW:Win32/QQPass.95498c13
Cybereasonmalicious.7e294a
BitDefenderThetaGen:NN.ZexaF.34698.kq0@aug7xGij
CyrenW32/QQPass.QSDB-4179
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.NPT
APEXMalicious
KasperskyTrojan.Win32.Agentb.aaup
BitDefenderGen:Variant.Johnnie.288192
NANO-AntivirusTrojan.Win32.Agent.bvubnw
AvastWin32:GenMaliciousA-CBI [Trj]
TencentTrojan.Win32.Agent.av
Ad-AwareGen:Variant.Johnnie.288192
EmsisoftGen:Variant.Johnnie.288192 (B)
ComodoMalware@#uccuc9tzik4g
BaiduWin32.Trojan-PSW.QQThief.a
VIPREGen:Variant.Johnnie.288192
TrendMicroTROJ_SPNR.03G313
McAfee-GW-EditionArtemis!Trojan
SophosTroj/PWS-CDW
IkarusTrojan-PWS.Win32.QQPass
GDataGen:Variant.Johnnie.288192
WebrootW32.Gen.pak
GoogleDetected
AviraTR/PSW.QQpass.nsanu
Antiy-AVLTrojan/Generic.ASMalwS.422
KingsoftWin32.Troj.Generic.z.(kcloud)
ArcabitTrojan.Johnnie.D465C0
ZoneAlarmTrojan.Win32.Agentb.aaup
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.QQPass.R71854
McAfeeArtemis!E47DC227E294
MAXmalware (ai score=100)
VBA32Trojan.PSW.22617
TrendMicro-HouseCallTROJ_SPNR.03G313
RisingStealer.QQPass!8.F7 (CLOUD)
YandexTrojan.GenAsa!p4i5IcsR3pc
FortinetW32/QQPass.NQB!tr
AVGWin32:GenMaliciousA-CBI [Trj]
PandaGeneric Malware

How to remove Johnnie.288192?

Johnnie.288192 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment