Malware

About “Johnnie.381470” infection

Malware Removal

The Johnnie.381470 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.381470 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Johnnie.381470?


File Info:

crc32: A4C68225
md5: 170646e0ebf77f566e69ada603dd10a8
name: 170646E0EBF77F566E69ADA603DD10A8.mlw
sha1: bcffd482215e52f28ddd02cf27d8cb34e49f7681
sha256: d461edf7fafa8c8643c61ea0e714456597a1eb9a5e1998e5b42ecc9d90435ba5
sha512: a54a074828eff03a4c749d01d40cbe70651191c01610123e4fbb894e92c4b8c46790c040ef7844fbeade7bf0b9a4d8bc2e32965973c75715b75a419c949495af
ssdeep: 12288:C63C0Oa97F+gYZp/a5M6i0/PcnEC0Oa97:a0OaX+BPym6i0sV0Oa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright Team Nemesisxa9 2018
Assembly Version: 1.0.0.0
InternalName: NemeCryptor.exe
FileVersion: 1.0.0.0
CompanyName: Team Nemesis
LegalTrademarks:
Comments:
ProductName: NemeCryptor
ProductVersion: 1.0.0.0
FileDescription: NemeCryptor
OriginalFilename: NemeCryptor.exe

Johnnie.381470 also known as:

K7AntiVirusTrojan ( 005389051 )
ALYacGen:Variant.Johnnie.381470
CylanceUnsafe
ZillyaTool.FakeFilecoder.Win32.50
AlibabaRiskWare:Win32/FakeRansom.06667697
K7GWTrojan ( 005389051 )
Cybereasonmalicious.0ebf77
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Hoax.FakeFilecoder.CG
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Hoax.Win32.Generic
BitDefenderGen:Variant.Johnnie.381470
NANO-AntivirusRiskware.Win32.FakeRansom.eyclmd
MicroWorld-eScanGen:Variant.Johnnie.381470
TencentWin32.Trojan-psw.Fakeransom.Dvpu
Ad-AwareGen:Variant.Johnnie.381470
SophosGeneric PUA LM (PUA)
ComodoMalware@#2ov8yg6q5fy27
BitDefenderThetaGen:NN.ZemsilF.34142.zm0@aiLDFpd
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGen:Variant.Johnnie.381470
EmsisoftGen:Variant.Johnnie.381470 (B)
JiangminHoax.FakeRansom.ab
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Johnnie.381470
McAfeeArtemis!170646E0EBF7
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
YandexRiskware.Hoax!ZUqwlzdjT5E
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Filecoder.CG
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Johnnie.381470?

Johnnie.381470 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment