Malware

Johnnie.292389 removal tips

Malware Removal

The Johnnie.292389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.292389 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • A scripting utility was executed
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Johnnie.292389?


File Info:

crc32: 4D961A05
md5: 76f547c793b5478b970c64caf04d01d4
name: 76F547C793B5478B970C64CAF04D01D4.mlw
sha1: f9eb40f6d3d4c83852e3781886db762bef8564e0
sha256: e7c277aae66085f1e0c4789fe51cac50e3ea86d79c8a242ffc066ed0b0548037
sha512: 91e91a8b693cb253f281411260611a221a113b342eaa642a9d6597aaf86c138ee2aa28ade10218a814ae34016e6d70824e36786497476ab704defddf60e33e17
ssdeep: 6144:Q5fW8eILySdSS4JoHjnJVZJQQIreKsuKu3a2WQe0gz+Y:OeILzSS5jnJ/JTu3zWtqY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: QuantumQuditSimulator
FileVersion: 1.0.0.42
CompanyName: Damo Inc
ProductName: Quantum Qudit Simulator
ProductVersion: 1.0.0.42
OriginalFilename: QuantumQuditSimulator.exe

Johnnie.292389 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Johnnie.292389
CAT-QuickHealTrojan.Vebzenpak
McAfeeArtemis!76F547C793B5
CylanceUnsafe
K7AntiVirusTrojan ( 005735561 )
BitDefenderGen:Variant.Johnnie.292389
K7GWTrojan ( 005735561 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Johnnie.D47625
TrendMicroTROJ_GEN.R002C0DKI20
BitDefenderThetaGen:NN.ZevbaF.34634.Hm0@ay9Vfvai
CyrenW32/Trojan.XEQU-1929
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Johnnie-9797515-0
KasperskyTrojan.Win32.Vebzenpak.abxn
AlibabaTrojan:Win32/Vebzenpak.ac5e1d02
ViRobotTrojan.Win32.S.MountLocker.544768
Ad-AwareGen:Variant.Johnnie.292389
EmsisoftGen:Variant.Johnnie.292389 (B)
ComodoMalware@#2jsh0lk8b55tb
F-SecureTrojan.TR/Kryptik.ofwjj
DrWebTrojan.Encoder.33163
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Trojan.hh
FireEyeGeneric.mg.76f547c793b5478b
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.109696731.susgen
AviraTR/Kryptik.ofwjj
KingsoftWin32.Troj.Vebzenpak.ab.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Skeeyah!MSR
AegisLabTrojan.Win32.Vebzenpak.4!c
ZoneAlarmTrojan.Win32.Vebzenpak.abxn
GDataGen:Variant.Johnnie.292389
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/GenKryptik.EWOG
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=100)
MalwarebytesRansom.FileCryptor
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKI20
TencentMalware.Win32.Gencirc.11b16bb8
IkarusTrojan.Win32.Krypt
FortinetW32/Vebzenpak.ABXN!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.d61

How to remove Johnnie.292389?

Johnnie.292389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment