Malware

Should I remove “Johnnie.296192”?

Malware Removal

The Johnnie.296192 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.296192 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Johnnie.296192?


File Info:

crc32: 1B9D2D35
md5: 692e87108943be39e3e6b93862e95aa5
name: 692E87108943BE39E3E6B93862E95AA5.mlw
sha1: 6ca6808e5b190b24132cf0ba7fe1db50610cc0eb
sha256: 8fb72cecd16ea32e163cdb6f633f92444d995fd0b6dfdc56bdbc66d38bb72e46
sha512: e101c2a925544cf080e821d4f401a6d2e8abe2c7ae8746b631564817d9d91c4fcd8dcacbfc802edc8ccd04dc958c635aad069328c8f3eedb4055ca4686fc24e7
ssdeep: 6144:nsAOiD9HH9Y21fYeENmSxp9LP/+sXXXXXi3PN1wk:sJk9HHPfdGmSP9jWsXXXXXoNek
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Mountshare xa9 2014 Girlpay
InternalName: Heard Second
FileVersion: 1.6.5.177
CompanyName: Danger say
ProductName: Section.dll
ProductVersion: 1.6.5.177
FileDescription: Mountshare
Translation: 0x0409 0x04b0

Johnnie.296192 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.296192
FireEyeGen:Variant.Johnnie.296192
McAfeeArtemis!692E87108943
SangforMalware
BitDefenderGen:Variant.Johnnie.296192
CyrenW32/Trojan.LJPD-5198
SymantecTrojan.Gen.MBT
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
AlibabaTrojanBanker:Win32/Cridex.edc7f6e8
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Babar.Wnwo
Ad-AwareGen:Variant.Johnnie.296192
SophosMal/Generic-S
F-SecureTrojan.TR/Banker.Cridex.yrncr
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Johnnie.296192 (B)
WebrootW32.Malware.Gen
AviraTR/Banker.Cridex.yrncr
MAXmalware (ai score=80)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA8F
GridinsoftTrojan.Win32.Dropper.oa
ArcabitTrojan.Johnnie.D48500
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataGen:Variant.Johnnie.296192
CynetMalicious (score: 85)
ALYacGen:Variant.Johnnie.296192
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.FBLRYPK
IkarusTrojan.SuspectCRC
FortinetW32/Generik.FBLRYPK!tr
AVGFileRepMalware
Qihoo-360Win32/Trojan.8a8

How to remove Johnnie.296192?

Johnnie.296192 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment