Malware

What is “Johnnie.5128”?

Malware Removal

The Johnnie.5128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.5128 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Puerto Rico)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Johnnie.5128?


File Info:

name: 05E87FA5BF5FEA4D08F5.mlw
path: /opt/CAPEv2/storage/binaries/638298097b1d8dc8f6c16c89de4b1aecef20c86f0b26a6ac4cb02b5ebcdad196
crc32: 758FB1A6
md5: 05e87fa5bf5fea4d08f57a622d45ef78
sha1: 330d84612ac8455c7f1564b380afce48cfe01c6f
sha256: 638298097b1d8dc8f6c16c89de4b1aecef20c86f0b26a6ac4cb02b5ebcdad196
sha512: 60cb66107738423682f396d64fe5fe13ee8516370969c6f35091b631e411a1ef59884abe881993ff9a68fd980199ad5798e019e8b5ee086d1b4bd05260da2e06
ssdeep: 768:TuFxbzEsy9wmsGaxFIkud+e9WigswDUMKiFIk6chisiOeGHRNZ1RXMNPYn6lFFgn:6Isyay0BzZ10XYVM+Zx9sa1SU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E93AD7B73DB0DF8F20A9C74AA8786CA86BE31020B4F7493193C16359C5BE444A6D57B
sha3_384: d00f1e5d3c2545450cf57c4ecca6c9ce9c5b4f8964c534b98bca8ea1bab8336f522817d0036826cbad131bd1d2c0d95a
ep_bytes: 6880114000e8eeffffff000000000000
timestamp: 2010-12-07 16:36:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: yTTxCE
FileVersion: 9.80
ProductVersion: 9.80
InternalName: uTTxCE
OriginalFilename: uTTxCE.exe

Johnnie.5128 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.5128
FireEyeGeneric.mg.05e87fa5bf5fea4d
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.mt
McAfeeVBObfus.c
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001db3841 )
K7GWTrojan ( 001db3841 )
Cybereasonmalicious.5bf5fe
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Shiru.AI
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.XM
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIB
ClamAVWin.Trojan.VB-1375
KasperskyWorm.Win32.VBNA.brrb
BitDefenderGen:Variant.Johnnie.5128
NANO-AntivirusTrojan.Win32.Autoruner.covkyu
AvastWin32:VB-QOE [Trj]
TACHYONTrojan/W32.VB-VBKrypt.90112
SophosW32/SillyFDC-FM
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.37681
VIPREGen:Variant.Johnnie.5128
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Johnnie.5128 (B)
IkarusTrojan.ATRAPS
JiangminWorm/VBNA.gyuy
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.L.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Autorun.VA@2o7hyt
ArcabitTrojan.Johnnie.D1408
ViRobotTrojan.Win32.A.VBKrypt.90112.BU
ZoneAlarmWorm.Win32.VBNA.brrb
GDataWin32.Trojan.VB.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R5408
BitDefenderThetaAI:Packer.8C26E84A20
ALYacGen:Variant.Johnnie.5128
MAXmalware (ai score=86)
VBA32SScope.Trojan.VBRA.5166
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.FM
RisingWorm.VobfusEx!1.99EB (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QOE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Johnnie.5128?

Johnnie.5128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment