Malware

About “Johnnie.290418” infection

Malware Removal

The Johnnie.290418 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.290418 virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

How to determine Johnnie.290418?


File Info:

crc32: 45F5652F
md5: a94488e3a568d2e12fd13fe90a656478
name: A94488E3A568D2E12FD13FE90A656478.mlw
sha1: c6599af162d89db4e362cbd43fcc454892ae3de5
sha256: e99899927b1f1d9ff82df1a2259ebc7d0c13854faed6218af3f7cfd043e305b8
sha512: 5a54fab78561ee49f4dd962d386aa927739b2a06d2dd987fab0ff033b0436acc3f98dbd974af1bae840c05645eb6371724e510fa7f98b2ad46adc991900c29bd
ssdeep: 12288:jCQeW3oONbP0I8nOF5FT8Uxx/+ewaLWCWhbs:jqqv84fTjrLLs9s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 1
FileVersion: 1.00
CompanyName: Harmmy Coder
ProductName: Program
ProductVersion: 1.00
OriginalFilename: 1.exe

Johnnie.290418 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0056cb291 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.58303
CynetMalicious (score: 90)
CAT-QuickHealTrojan.VBCrypt.MF.79
ALYacGen:Variant.Johnnie.290418
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.11997
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWP2PWorm ( 004e48a21 )
Cybereasonmalicious.3a568d
CyrenW32/Rbot.A.gen!Eldorado
ESET-NOD32Win32/AutoRun.VB.BDD
APEXMalicious
AvastWin32:Keylog-B [Trj]
ClamAVWin.Malware.Zusy-6853855-0
KasperskyWorm.Win32.VBNA.b
BitDefenderGen:Variant.Johnnie.290418
NANO-AntivirusTrojan.Win32.Blocker.dxvjlw
SUPERAntiSpywareTrojan.Agent/Gen-Cryptor
MicroWorld-eScanGen:Variant.Johnnie.290418
TencentMalware.Win32.Gencirc.10b74edd
Ad-AwareGen:Variant.Johnnie.290418
SophosML/PE-A + Troj/KeyLgr-A
BitDefenderThetaAI:Packer.E7CB51BC1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.jh
FireEyeGeneric.mg.a94488e3a568d2e1
EmsisoftGen:Variant.Johnnie.290418 (B)
JiangminTrojan/Blocker.guu
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Johnnie.D46E72
ZoneAlarmWorm.Win32.VBNA.b
GDataGen:Variant.Johnnie.290418
TACHYONTrojan/W32.VB-Blocker.618496
AhnLab-V3Trojan/Win32.Blocker.R85723
McAfeeGenericR-CWB!A94488E3A568
MAXmalware (ai score=89)
VBA32Malware-Cryptor.VB.gen.1
RisingWorm.Autorun!8.50 (TFE:dGZlOgUbrCnS9oHSoQ)
YandexTrojan.GenAsa!/sWb19iZGJQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1231436.susgen
FortinetW32/VB.BDD!tr
AVGWin32:Keylog-B [Trj]
Qihoo-360HEUR/QVM03.0.1DE8.Malware.Gen

How to remove Johnnie.290418?

Johnnie.290418 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment