Malware

Johnnie.378403 (file analysis)

Malware Removal

The Johnnie.378403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.378403 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Johnnie.378403?


File Info:

crc32: 23A0A308
md5: 119871f37ed66fc243564c20a4ba2f70
name: 119871F37ED66FC243564C20A4BA2F70.mlw
sha1: bba622d4df053e63efaba1a5ae738139c984d7dd
sha256: a37cd5f482696542a9aae7bbfe534147d6cefa657aa48b03aac78e526903ff23
sha512: ad2b9d0fd71b51f17d7ba0b33805c9125e23618010ce9edc85a2a3c1f5ecbe65123b43233e87d89494bca7c535b0bc61a3387d042525d1fab1f12728cffa4cca
ssdeep: 3072:dPYIH+ui7/+2OcrnsorHhRvQdlcgU9WOKz:RfO/+7c7sIHhRodi3C
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: Windows.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Windows
ProductVersion: 1.0.0.0
FileDescription: Windows
OriginalFilename: Windows.exe

Johnnie.378403 also known as:

K7AntiVirusTrojan ( 0057c00b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Johnnie.378403
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057c00b1 )
Cybereasonmalicious.37ed66
CyrenW32/MSIL_Kryptik.CRZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FEXV
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Johnnie.378403
MicroWorld-eScanGen:Variant.Johnnie.378403
Ad-AwareGen:Variant.Johnnie.378403
SophosML/PE-A
ComodoBackdoor.Win32.IRCBot.AQ@4pji73
BitDefenderThetaGen:NN.ZemsilF.34088.gm0@ae4OsKd
TrendMicroTROJ_GEN.R014C0WH221
McAfee-GW-EditionRDN/Generic.rp
FireEyeGeneric.mg.119871f37ed66fc2
EmsisoftGen:Variant.Johnnie.378403 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129983
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Johnnie.378403
AhnLab-V3Trojan/Win.Generic.C4576411
McAfeeRDN/Generic.rp
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R014C0WH221
IkarusWorm.Win32.Rebhip
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.PEI!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Johnnie.378403?

Johnnie.378403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment