Malware

Ser.Johnnie.5361 information

Malware Removal

The Ser.Johnnie.5361 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Johnnie.5361 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

cdn.arsis.at
www.bing.com

How to determine Ser.Johnnie.5361?


File Info:

crc32: 58E1B21C
md5: d6c361f547a7c56c40791098cec92186
name: tmppwt8b2cr
sha1: 4717f01ae2a558a00d509fe184d9f93bb8043e3a
sha256: 7bc9d1453bb84033fd82500f10db64cbf221c4286ed3eba7928249dae6d67675
sha512: 5a3fd95aa0acb9c315bb1eb9312a8c1d2f23770ccdf9e1da0544aa7d06a2332c423a3916cd2d6253f8a387348988a1a3274103c5a19719a06e9f6097c353ab99
ssdeep: 3072:Ap1FkFamt9H3vAmdKWEfz2BsY4DcflDonb5oDZZQyK3tumnwD:a1FkFamz3omMWKz2BR46ZZQyKK
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: sd fdsi fds fjsd fdsfj kldsfj kldjs fdjsklfdjsf
InternalName: d fds f8dsf8 0dsf8 90ds8 fsd8f90 sd890 fds9f s90d8s90d8f
FileVersion: ds fds9f8 ds f80ds8 f9ds8 f0ds8f0 sd8f9sd90f ds098 f
PrivateBuild: ds f98ds f8s90d8f 9ds8f0 s8d0 f89sd8f ds890f 8dsf8 90ds8 f
LegalTrademarks: sd fsd8-0 fds f90-ds9 f0ds9f ds9f0-9ds f9ds9 f-ds90 fds- f9
ProductName: sd fiusd fpdsfpd;sf dsf dsfkodskop fkds fdsfk dsfk
ProductVersion: sd fods fods fdks fdoskf kdsf pdskf dsfo dks f
FileDescription: SDF DS 9F8DS98 FDS98 F90DSF89DS8F9DS8F9 8DS0F80DS9
OriginalFilename: sd fds fdsjf ddfs fsdf dsi fds fdsfj dksj fdlsfj ldsjf ksdj f
Translation: 0x0419 0x04b0

Ser.Johnnie.5361 also known as:

MicroWorld-eScanGen:Variant.Ser.Johnnie.5361
CAT-QuickHealTrojan.Gozi
Qihoo-360Generic/Trojan.028
ALYacSpyware.Ursnif
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Gozi.7!c
SangforMalware
K7AntiVirusSpyware ( 005526431 )
BitDefenderGen:Variant.Ser.Johnnie.5361
K7GWSpyware ( 005526431 )
TrendMicroTrojanSpy.Win32.URSNIF.THFAHBO
CyrenW32/Trojan.KNTN-1468
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Ursnif.CT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Gozi.kxj
AlibabaTrojanBanker:Win32/Ursnif.3a694861
RisingSpyware.Ursnif!8.1DEF (CLOUD)
Ad-AwareGen:Variant.Ser.Johnnie.5361
EmsisoftGen:Variant.Ser.Johnnie.5361 (B)
ComodoMalware@#14lf79j63cdgw
F-SecureHeuristic.HEUR/AGEN.1108818
Invinceaheuristic
FireEyeGeneric.mg.d6c361f547a7c56c
SophosTroj/Gozi-TP
IkarusTrojan.Win32.Kovter
JiangminTrojan.Banker.Gozi.atr
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1108818
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Gozi
MicrosoftTrojanSpy:Win32/Ursnif.KC!bit
ArcabitTrojan.Ser.Johnnie.D14F1
ZoneAlarmTrojan-Banker.Win32.Gozi.kxj
GDataGen:Variant.Ser.Johnnie.5361
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4132477
McAfeeRDN/Generic PWS.y
VBA32TrojanBanker.Gozi
MalwarebytesTrojan.Ursnif
PandaTrj/RnkBend.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.THFAHBO
TencentWin32.Trojan.Inject.Auto
FortinetW32/Ursnif.CT!tr.spy
BitDefenderThetaGen:NN.ZexaF.34130.oq3@aSsQp7kc
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.102470225.susgen

How to remove Ser.Johnnie.5361?

Ser.Johnnie.5361 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment