Malware

What is “Johnnie.95104”?

Malware Removal

The Johnnie.95104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.95104 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Johnnie.95104?


File Info:

crc32: 912691BB
md5: 9f15a2718640cc2dd9c08ed1cdb924c0
name: 9F15A2718640CC2DD9C08ED1CDB924C0.mlw
sha1: 60935615745b64a6c70e08dca2ff7bc2cbf2529d
sha256: 21783156c8db404696aacfe193ba5b30ab3214b0db4c827a8a79f8db61e1988c
sha512: 6b6d093c428f06632717e3445d7a17251cd352e4ca27e8a7967b13ef9b3436fb63186315bc81675427ec1a7d5f31e08de442c3bbe26a6d803d27640868aecd69
ssdeep: 3072:fDjabtcLayLXD6riZiW4NaBZdZj+gnza:fyb4CNaBZCr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.95104 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f3c81 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Urausy.C
ALYacGen:Variant.Johnnie.95104
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.4726
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Urausy.141d1513
K7GWTrojan ( 0040f3c81 )
Cybereasonmalicious.18640c
CyrenW32/FakeAlert.WR.gen!Eldorado
SymantecTrojan.Ransomlock.Q!g1
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:Reveton-RI [Trj]
ClamAVWin.Ransomware.Generickdz-9652427-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Johnnie.95104
NANO-AntivirusTrojan.Win32.Winlock.cqlfzd
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
MicroWorld-eScanGen:Variant.Johnnie.95104
TencentMalware.Win32.Gencirc.10b54fef
Ad-AwareGen:Variant.Johnnie.95104
SophosML/PE-A + Mal/FakeAV-ST
ComodoTrojWare.Win32.Ransom.Foreign.SEA@4xzjgq
BitDefenderThetaGen:NN.ZexaF.34628.guW@aK970Wfi
VIPRETrojan.Win32.FakeAV.ka (v)
TrendMicroTROJ_RANSOM.SMMA
McAfee-GW-EditionBehavesLike.Win32.FakeSecTool.ch
FireEyeGeneric.mg.9f15a2718640cc2d
EmsisoftGen:Variant.Johnnie.95104 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Foreign.gne
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen8
KingsoftWin32.Troj.GenericKDZ.v.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AFQ
ArcabitTrojan.Johnnie.D17380
AegisLabTrojan.Win32.Generic.lJAM
GDataGen:Variant.Johnnie.95104
TACHYONTrojan/W32.Foreign.106496.R
AhnLab-V3Trojan/Win32.Foreign.R68268
Acronissuspicious
McAfeeFake-SecTool!9F15A2718640
MAXmalware (ai score=100)
VBA32BScope.Trojan.Winlock
MalwarebytesTrojan.MalPack.LDGA
PandaTrj/Resdec.HEU
TrendMicro-HouseCallTROJ_RANSOM.SMMA
RisingTrojan.Agent!1.69A7 (CLOUD)
YandexTrojan.GenAsa!drr44/oOGcI
IkarusTrojan.Win32.Urausy
FortinetW32/FakeAV.SE!tr
AVGWin32:Reveton-RI [Trj]
Qihoo-360Win32/Ransom.Urausy.HwgAEpsA

How to remove Johnnie.95104?

Johnnie.95104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment