Malware

About “Johnnie.29608” infection

Malware Removal

The Johnnie.29608 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.29608 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Detects VMware through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
ht.suzip.cn
a.tomx.xyz

How to determine Johnnie.29608?


File Info:

crc32: 8B32C1A3
md5: e9b22ee8e38b7f9f9413589ab7774116
name: yasuo_103.exe
sha1: 6047bb0e53ac4074a86b03a5d200e9211707ad0c
sha256: 68b76906022609f03019d2b04bdfc6720fffad22138f5720b0fa200651434ed6
sha512: 63ff85de6fb04d158916ff7542e6abaace017f82a3ca394be8a34964414f8b6959ba355827f5c09b23b2192e58fafe49ae0879afd1e9abbd8720023f9836e4b5
ssdeep: 98304:H4On+PoPpTLq0M0ww89V5v6jP9uApHS408R:YO8elLq90ww8kjcABj0U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Xun_Tux7248x6743x6240x6709
ProductVersion: 1.0.0.1
ProductName: ji_sux538bx7f29
FileVersion: 1.0.0.1
FileDescription: ji_sux538bx7f29
Translation: 0x0804 0x03a8

Johnnie.29608 also known as:

MicroWorld-eScanGen:Variant.Johnnie.29608
CAT-QuickHealPua.Sogou
McAfeeArtemis!E9B22EE8E38B
VIPREAdware.Sogou
K7GWTrojan ( 005146801 )
K7AntiVirusTrojan ( 005146801 )
ArcabitTrojan.Johnnie.D73A8
TrendMicroTROJ_GEN.R00AC0OJ917
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R00AC0OJ917
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Johnnie.29608
Kasperskynot-a-virus:AdWare.Win32.Sogou.qn
BitDefenderGen:Variant.Johnnie.29608
Paloaltogeneric.ml
Ad-AwareGen:Variant.Johnnie.29608
EmsisoftGen:Variant.Johnnie.29608 (B)
F-SecureGen:Variant.Johnnie.29608
DrWebAdware.ShouQu.5
ZillyaAdware.GenericKDCRTD.Win32.12133
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA GA (PUA)
IkarusPUA.NSISmod
CyrenW32/Adware.MMKH-2199
WebrootW32.Adware.Gen
AviraADWARE/Xpyn.sijbv
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.e
Endgamemalicious (high confidence)
ViRobotAdware.Sogou.3321104
ZoneAlarmnot-a-virus:AdWare.Win32.Sogou.qn
AhnLab-V3PUP/Win32.Installer.C2006866
ALYacGen:Variant.Johnnie.29608
AVwareAdware.Sogou
MAXmalware (ai score=100)
VBA32AdWare.Sogou
ESET-NOD32a variant of Win32/Packed.NSISmod.AL suspicious
eGambitUnsafe.AI_Score_91%
FortinetAdware/Sogou
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.1b8fb7
PandaTrj/CI.A
CrowdStrikemalicious_confidence_90% (D)

How to remove Johnnie.29608?

Johnnie.29608 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment