Malware

What is “Johnnie.79198”?

Malware Removal

The Johnnie.79198 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.79198 virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Johnnie.79198?


File Info:

name: CCCC7A57F53DED70B34D.mlw
path: /opt/CAPEv2/storage/binaries/9801f111d2f6979d91140845f9423153ab7089fee44b1fce15e6363249cee6f2
crc32: F8A7ADC3
md5: cccc7a57f53ded70b34dd31a432658e6
sha1: 51f30026ab731fabc0f6d0b4fc333fb862c8d7e7
sha256: 9801f111d2f6979d91140845f9423153ab7089fee44b1fce15e6363249cee6f2
sha512: a05305bb23a81cf9d14c66f5034308398f36a4291e870ff75ffdfd42d100d0c8a120509f0d49d26ee0f8a841c0b679a821044b82636d2a53d2a34163096674f4
ssdeep: 6144:iyZ8sDVIHahKpD69jxfl0u2HdjuEEHvMXGklDtKfiPzh:iyNmHCK2j52HdCxvzklDtK6d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14654243DE3034456E319E7B10B02E9F0C9564C3A47A4F04FE76AB83AA93119F597726E
sha3_384: 56969b8e00c96770b181744b2d7a3cac3a7611becc05836620741399adbc82a34cf1114a5b975e81653d4b47efc19cff
ep_bytes: 6a606840514000e880030000bf940000
timestamp: 2012-05-08 19:16:13

Version Info:

0: [No Data]

Johnnie.79198 also known as:

MicroWorld-eScanGen:Variant.Johnnie.79198
FireEyeGeneric.mg.cccc7a57f53ded70
ALYacGen:Variant.Johnnie.79198
MalwarebytesMalware.AI.3818947484
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Dropper.Gen
K7AntiVirusTrojan ( 00572c171 )
AlibabaVirTool:Win32/Injector.8a9731f3
K7GWTrojan ( 00572c171 )
Cybereasonmalicious.7f53de
BitDefenderThetaGen:NN.ZexaF.34212.sqX@a8Fa8pcc
VirITTrojan.Win32.Packed.BHFY
CyrenW32/CeeInject.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAQ
APEXMalicious
ClamAVWin.Trojan.Zbot-47418
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Johnnie.79198
NANO-AntivirusTrojan.Win32.Panda.rhlan
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:Citadel [Trj]
TencentMalware.Win32.Gencirc.10c43ac6
Ad-AwareGen:Variant.Johnnie.79198
EmsisoftGen:Variant.Johnnie.79198 (B)
ComodoTrojWare.Win32.Spy.Zbot.RQ@4oxbl6
DrWebTrojan.Packed.22462
ZillyaTrojan.Zbot.Win32.60647
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
SophosMal/Generic-S
IkarusVirus.Win32.Injector
GDataGen:Variant.Johnnie.79198
JiangminTrojan/Generic.abqos
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1E7FDA
ArcabitTrojan.Johnnie.D1355E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Injector.AX
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R27390
Acronissuspicious
McAfeePWS-Zbot.gen.bfo
MAXmalware (ai score=99)
VBA32TrojanDropper.Injector
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!tT/dERNO71g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.AFVU!tr
WebrootW32.Rogue.Gen
AVGWin32:Citadel [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Johnnie.79198?

Johnnie.79198 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment