Categories: Malware

Johnnie.336512 removal instruction

The Johnnie.336512 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.336512 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial language used in binary resources: Icelandic
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Johnnie.336512?


File Info:

crc32: E9B17D05md5: c2ec509cdd866e8d0ac4c0c9ff3fec6bname: C2EC509CDD866E8D0AC4C0C9FF3FEC6B.mlwsha1: cd614d53abbb77b35fe2e9f618dc9de2177bff15sha256: b71193c5fba69754cbd31f5b3c3e482830c3337f4d734087729a7ea51cc4ba0esha512: 4f2f34f5a3c63606b019bd7306d8070848757c1ea09a952375842b0d6247724b03346c145248893027526c7585ca606a225b2b4831914f35d4409d8defff2908ssdeep: 24576:cn46FTDxWNsJUep5bFsxUvxRdyEdIm5VgoHsrO1:cnxFTtWWJUohCwvyBmD/ctype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmiiloku.apaProductVersion: 7.12.29.123Copyright: Copyrighz (C) 2021, fudkagetaTranslation: 0x0181 0x009f

Johnnie.336512 also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 0056f9be1 )
Elastic malicious (high confidence)
ALYac Gen:Variant.Johnnie.336512
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Gen:Variant.Johnnie.336512
K7GW Trojan ( 0056f9be1 )
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan.Win32.Chapak.gen
MicroWorld-eScan Gen:Variant.Johnnie.336512
Ad-Aware Gen:Variant.Johnnie.336512
Sophos ML/PE-A
BitDefenderTheta Gen:NN.ZexaF.34126.lr0@aqpOB!aG
McAfee-GW-Edition BehavesLike.Win32.Lockbit.tc
FireEye Generic.mg.c2ec509cdd866e8d
Emsisoft Gen:Variant.Johnnie.336512 (B)
SentinelOne Static AI – Malicious PE
Avira HEUR/AGEN.1139760
eGambit Unsafe.AI_Score_60%
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Arcabit Trojan.Johnnie.D52280
GData Gen:Variant.Johnnie.336512
MAX malware (ai score=89)
Malwarebytes MachineLearning/Anomalous.97%
Rising Trojan.Kryptik!1.D91D (CLASSIC)
Ikarus Trojan-Banker.UrSnif

How to remove Johnnie.336512?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Should I remove “Win32/Agent_AGen.DMX”?

The Win32/Agent_AGen.DMX is considered dangerous by lots of security experts. When this infection is active,…

51 seconds ago

What is “HackTool:Win32/NetCatTool!MTB”?

The HackTool:Win32/NetCatTool!MTB is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Malware.AI.1247929956 information

The Malware.AI.1247929956 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Packed.Win32.Krap.an information

The Packed.Win32.Krap.an is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Win32:AutoRun-AYS [Wrm] removal guide

The Win32:AutoRun-AYS [Wrm] is considered dangerous by lots of security experts. When this infection is…

1 hour ago

Win32/StartPage.OUR information

The Win32/StartPage.OUR is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago