Malware

Should I remove “Johnnie.299020”?

Malware Removal

The Johnnie.299020 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.299020 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Johnnie.299020?


File Info:

crc32: 788069E2
md5: 274ff9a5a2e1fb10fa67846dd3e62774
name: 274FF9A5A2E1FB10FA67846DD3E62774.mlw
sha1: 16cc00fb105d9dccf59d58b83afaf77996ee0766
sha256: 7928fb0bd83d9f0a65e8f3a5c5c262a10eeb2cd5306fd7ed35dbfdbb3042685e
sha512: 1e85e47a4e14f32131f705c905f7b6cadbfeb6faa379e6941741516bb71789bc3ea49c1b5eb9716599a9b4b31178988b5596ba2db1a967634c46d60a4cc6f9be
ssdeep: 6144:IsYj6b2J8dOJ5F6taJ6OiYvRhWC1OhMrccQubGad6BRk:ojcdbQJ6OiYvmCMUc7uyFRk
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Johnnie.299020 also known as:

K7AntiVirusTrojan ( 004cecf51 )
LionicAdware.JS.Agent.2!c
Elasticmalicious (high confidence)
DrWebTrojan.BPlug.1022
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.433418
CylanceUnsafe
ZillyaTrojan.ExtenBro.Win32.64628
SangforTrojan.Win32.Generic.rg
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaAdWare:Win32/ExtenBro.33498503
K7GWTrojan ( 004cecf51 )
Cybereasonmalicious.5a2e1f
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:UDS:AdWare.JS.Agent.et
BitDefenderGen:Variant.Johnnie.299020
NANO-AntivirusTrojan.Win32.ExtendBro.dxjgsm
ViRobotTrojan.Win32.Z.Extenbro.350234
MicroWorld-eScanGen:Variant.Johnnie.299020
TencentWin32.Trojan.Extenbro.Hqcd
SophosMal/Generic-S
ComodoMalware@#2fag56cawpclt
BitDefenderThetaGen:NN.ZedlaF.34170.gu4@aO6mjVfi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGen:Variant.Johnnie.299020
EmsisoftGen:Variant.Johnnie.299020 (B)
JiangminTrojan/ExtenBro.lf
AviraHEUR/AGEN.1124323
eGambitGeneric.Malware
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Johnnie.D4900C
GDataGen:Variant.Bulz.433418
AhnLab-V3PUP/Win32.Helper.R161101
McAfeeArtemis!274FF9A5A2E1
MAXmalware (ai score=83)
VBA32Trojan.ExtenBro
MalwarebytesMalware.AI.3604868526
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIT21
RisingTrojan.Generic@ML.81 (RDML:XU4t/mxlNTXnD+leupDRDg)
YandexTrojan.ExtenBro!a4JLI/BSQhM
SentinelOneStatic AI – Malicious PE
FortinetW32/ExtenBro.BP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Johnnie.299020?

Johnnie.299020 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment