Malware

About “Johnnie.9961” infection

Malware Removal

The Johnnie.9961 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.9961 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Johnnie.9961?


File Info:

name: 4B942E5DA252CB95EE04.mlw
path: /opt/CAPEv2/storage/binaries/ed09a52ac669906ace36376bc91805aea88b26256357c2bc11cb014f37d4da1d
crc32: 815CA233
md5: 4b942e5da252cb95ee04bf4a4869c290
sha1: 0c11cfee2818f4ca6cd78c1f35d56e592d3adad2
sha256: ed09a52ac669906ace36376bc91805aea88b26256357c2bc11cb014f37d4da1d
sha512: 16effdc132f5fdeaab76a89e1f035387e4f224ae1d4a917558f319003dfa218a7e55fcbf0f65afc2e002605b5f3f215b4d60d3d51b46ebe514be6183c13d3e43
ssdeep: 768:fYB28EckaZoRVFQpnwEM6cGztfe7P5wFtr+g0XoWIkdMQZL:wBrEckapBM6dfeL5wFtSgy11dZZL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14743D926D9190036F175C4B1692693A7B4623C312A018D1BA78FFB583A31BE7B5F531F
sha3_384: ed3e0b16d772095b8e26b7421ec25d179640eb016de16ca4e90838be960694a648c62babe9d36ecff6457ad7e1498cd9
ep_bytes: 68381f4000e8f0ffffff000000000000
timestamp: 2014-12-08 03:09:35

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 微软中国
ProductName: 工程1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: emerga2014-1伲뿾늗휡⪁ꗰ嘚ROriginalFilenam
OriginalFilename: emerga2014-12-8-01.exe

Johnnie.9961 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Johnnie.9961
FireEyeGeneric.mg.4b942e5da252cb95
CAT-QuickHealTrojan.Dynamer.S9260
McAfeeGenericRXAA-CH!4B942E5DA252
CylanceUnsafe
VIPREGen:Variant.Johnnie.9961
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 004b9b5e1 )
AlibabaTrojan:Win32/PackBackdoor.2855ba70
K7GWP2PWorm ( 004b9b5e1 )
Cybereasonmalicious.da252c
CyrenW32/S-0774d6b1!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB.RUD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Johnnie.9961
NANO-AntivirusTrojan.Win32.VB.epvcoq
AvastWin32:Malware-gen
TencentWin32.Trojan.Crypt.Ewnw
Ad-AwareGen:Variant.Johnnie.9961
SophosMal/Generic-S
ComodoMalware@#iida5fztxpv4
TrendMicroTROJ_GEN.R067C0PJ522
McAfee-GW-EditionBehavesLike.Win32.Generic.qt
EmsisoftGen:Variant.Johnnie.9961 (B)
IkarusTrojan.Win32.VB
GDataGen:Variant.Johnnie.9961
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Dynamer.R201804
ALYacGen:Variant.Johnnie.9961
MAXmalware (ai score=83)
TrendMicro-HouseCallTROJ_GEN.R067C0PJ522
RisingTrojan.Win32.dmX.a (CLASSIC)
YandexTrojan.VB!QBfwSs5+M74
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.34875E!tr
BitDefenderThetaGen:NN.ZevbaF.34698.dm0@aSOSZqgb
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Johnnie.9961?

Johnnie.9961 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment