Malware

Johnnie.5128 malicious file

Malware Removal

The Johnnie.5128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.5128 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Puerto Rico)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Johnnie.5128?


File Info:

name: BA6495442C07752CA49E.mlw
path: /opt/CAPEv2/storage/binaries/f84bab8d4005678e3630f5fa00e62264e17e67ff8079521827fe96b26847c775
crc32: 8A19A590
md5: ba6495442c07752ca49e91b5f174e0c5
sha1: cc96f3fe4e1ca958210a97d7be6296c56b2e12b4
sha256: f84bab8d4005678e3630f5fa00e62264e17e67ff8079521827fe96b26847c775
sha512: 83ba8fc14836e47d9bb447ff1eca66477fd85c1a9fbc7ba5c6c15fae829889523497c50de7a226ca764c13ed5df6c0b77fd173edd913cfd86d2e49231ab37e33
ssdeep: 768:7uxxbz9j6lMwmsGaxFIkud+e9WigswDUMKiFIk6chisiOeGHRNZ1RXMNPYn6lFF/:Gxj6lVy0BzZ10XYVM+Zx9sa1CyfITh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C193AD6F73DB0DF8F20A9C74AA8786CA86BE31020B4F7493193C16359C5BE444A6D57B
sha3_384: 02d81df2ee7984b69db27216de559efaeb5361d174b0db15daf8ef9c66a83351d94dcedd6d1460150a8f87890a803f45
ep_bytes: 6880114000e8eeffffff000000000000
timestamp: 2010-12-07 16:36:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: yLDDNg
FileVersion: 4.21
ProductVersion: 4.21
InternalName: uLDDNg
OriginalFilename: uLDDNg.exe

Johnnie.5128 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.37681
MicroWorld-eScanGen:Variant.Johnnie.5128
FireEyeGeneric.mg.ba6495442c07752c
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.mt
McAfeeVBObfus.c
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001db3841 )
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001db3841 )
Cybereasonmalicious.42c077
BitDefenderThetaAI:Packer.8C26E84A20
VirITTrojan.Win32.Shiru.AI
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.XM
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIB
ClamAVWin.Trojan.VB-1375
KasperskyWorm.Win32.VBNA.brrb
BitDefenderGen:Variant.Johnnie.5128
NANO-AntivirusTrojan.Win32.Autoruner.covkyu
AvastWin32:VB-QOE [Trj]
TencentWorm.Win32.Wbna .16000410
TACHYONTrojan/W32.VB-VBKrypt.90112
EmsisoftGen:Variant.Johnnie.5128 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.AutoRun.cj
VIPREGen:Variant.Johnnie.5128
TrendMicroWORM_VOBFUS.SMIB
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-FM
IkarusTrojan.ATRAPS
JiangminWorm/VBNA.gyuy
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.L.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Autorun.VA@2o7hyt
ArcabitTrojan.Johnnie.D1408
ViRobotTrojan.Win32.A.VBKrypt.90112.BU
ZoneAlarmWorm.Win32.VBNA.brrb
GDataWin32.Trojan.VB.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R5408
VBA32SScope.Trojan.VBRA.5166
ALYacGen:Variant.Johnnie.5128
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.FM
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!lpdAkqOcu/w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QOE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.cd7df623

How to remove Johnnie.5128?

Johnnie.5128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment