Malware

How to remove “Johnnie.3442”?

Malware Removal

The Johnnie.3442 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.3442 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Johnnie.3442?


File Info:

name: 324B20C5120228EFCBDC.mlw
path: /opt/CAPEv2/storage/binaries/1077ee2908d276c9a046655610e2e5fdd62c49414dbd1effc511d3ffa8ebd751
crc32: 27DF06C4
md5: 324b20c5120228efcbdcb3768bd7f226
sha1: a6c5df2c78a79cd8bb55f562f9730c816b76d5ce
sha256: 1077ee2908d276c9a046655610e2e5fdd62c49414dbd1effc511d3ffa8ebd751
sha512: 025aed9fe9333386884293530dee3cafb3dc1360efe8b9b5115a31aadef26f94bdd120d0b0a326b1aed47a002fb6eb797ce32be657148d1d516354237407987f
ssdeep: 3072:gtH4Tv++xEFahwATnqq2PhRGRGhEk/DqDB6w7P9:gfEWM2RthXDCT9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F342AB958ECBD26CA256637428EC8944175BE3D3F926F9F398E3B2F13B51400191E39
sha3_384: 803c7b0a04935908f87ea176906b29f063098bddf949f77fea415505db6e90960f14c31e80ef5e603347d3dd3bfc2a54
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-03-23 17:12:17

Version Info:

Translation: 0x0000 0x04b0

Johnnie.3442 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.324b20c5120228ef
McAfeeGenericRXBP-EI!324B20C51202
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Binder.GW
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Johnnie.3442
NANO-AntivirusTrojan.Win32.VkBase.escarv
MicroWorld-eScanGen:Variant.Johnnie.3442
Ad-AwareGen:Variant.Johnnie.3442
DrWebTrojan.VkBase.120
EmsisoftGen:Variant.Johnnie.3442 (B)
GDataGen:Variant.Johnnie.3442
JiangminTrojan.Generic.ffac
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.A8395E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.MDA.C552631
BitDefenderThetaGen:NN.ZemsilF.34294.omW@ayAx38e
ALYacGen:Variant.Johnnie.3442
VBA32TrojanSpy.MSIL.KeyLogger
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.82B630!tr
AVGWin32:Malware-gen

How to remove Johnnie.3442?

Johnnie.3442 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment