Malware

Johnnie.291400 removal tips

Malware Removal

The Johnnie.291400 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.291400 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Johnnie.291400?


File Info:

crc32: C80BF8EE
md5: f54132690d7f929de69b2381e53ad5e5
name: F54132690D7F929DE69B2381E53AD5E5.mlw
sha1: fabcabcbc9e8f3b9165ae843b7e3f3f9cf476ba7
sha256: 20c45f547845b60ae703ece097a4be15da97cf6d4b9057b8cb76d4b66f2a527c
sha512: 624c738ffe3a4ed1bb6bda10c406461f59ca7b69cd694788c597fb2d41cab9880026dcc079adf1be4dc8703e884d7c997921ad307dddaae0db12db7f96701dfb
ssdeep: 49152:5s7l5pvA5dJrKOtQj4XGWdKIT9aP+4Mx9Jsf7e:5sHpvA5dJrlQj2xwS0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020 Shangrao Fengyun
InternalName: news.exe
FileVersion: 1.0.0.1
CompanyName: Shangrao Fengyun Network Technology Co., Ltd.
ProductName: jjbq
ProductVersion: 1.0.0.1
FileDescription: mininews
OriginalFilename: news.exe
Translation: 0x0804 0x04b0

Johnnie.291400 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.291400
ALYacGen:Variant.Johnnie.291400
CylanceUnsafe
ZillyaAdware.ComponentBased.Win32.298
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/ComponentBased.452d85bd
K7GWTrojan-Downloader ( 0056617b1 )
K7AntiVirusTrojan-Downloader ( 0056617b1 )
CyrenW32/Adload.FQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Adload.NUS
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
BitDefenderGen:Variant.Johnnie.291400
TencentMalware.Win32.Gencirc.10cee843
Ad-AwareGen:Variant.Johnnie.291400
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R035C0WJT21
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGeneric.mg.f54132690d7f929d
EmsisoftGen:Variant.Johnnie.291400 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.ComponentBased.ef
AviraHEUR/AGEN.1139822
Antiy-AVLTrojan/Generic.ASMalwS.336CE8F
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1MXIDN
AhnLab-V3Adware/Win.Agent.C4507661
McAfeeGenericRXPV-UW!F54132690D7F
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R035C0WJT21
YandexPUA.ComponentBased!RLJizYiIYUY
IkarusTrojan-Downloader.Win32.Adload
MaxSecureTrojan.Malware.74556039.susgen
FortinetW32/Adload.NUS!tr.dldr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Johnnie.291400?

Johnnie.291400 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment