Malware

Johnnie.342156 removal tips

Malware Removal

The Johnnie.342156 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.342156 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
romkaxarit.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Johnnie.342156?


File Info:

crc32: E62C9DE6
md5: ea25aa32aa08a715cea6a9629429b587
name: EA25AA32AA08A715CEA6A9629429B587.mlw
sha1: 59fe1e37011798dfe5e2af37d640581d71641312
sha256: 56fb6c3990b886950622f461bcd617b96f00bdfb90cb6426aabb01639c1fab59
sha512: 670027bf10d0f6e8bdb56689e62851dba3ae53d8d7c3fc939842ada6ac4b86f26414570bb7942d6ec35317c2b1c2cbe3b0c3dc068aabe10c423ea3b43b174365
ssdeep: 12288:UeOnLbfSwMfAMJ//EWnMIUaBKQJ5DTlziw5LxCeYPlWewZQayA:t0HHwMuUavl+w5Ld4lWewtyA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.342156 also known as:

Elasticmalicious (high confidence)
CAT-QuickHealRansom.Stop.Z5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Johnnie.342156
Cybereasonmalicious.701179
CyrenW32/Kryptik.EYC.gen!Eldorado
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Injuke.gen
MicroWorld-eScanGen:Variant.Johnnie.342156
Ad-AwareGen:Variant.Johnnie.342156
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34126.RqW@aCO0zOaO
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.ea25aa32aa08a715
EmsisoftGen:Variant.Johnnie.342156 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Johnnie.342156
VBA32BScope.Trojan.Chapak
MAXmalware (ai score=88)
RisingTrojan.Generic@ML.100 (RDML:GWTWNBIMwFuaa9qUzCSXzA)
IkarusTrojan.Win32.Azorult

How to remove Johnnie.342156?

Johnnie.342156 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment