Backdoor

Backdoor:Win32/Venik.J (file analysis)

Malware Removal

The Backdoor:Win32/Venik.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Venik.J virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Backdoor:Win32/Venik.J?


File Info:

name: 107F36B0CDD241D0F3C5.mlw
path: /opt/CAPEv2/storage/binaries/433456aea2b9b097b0bf6bc8c16a43416d6d46477c6b510f58835aa775741013
crc32: DC665467
md5: 107f36b0cdd241d0f3c5fb95e1105c70
sha1: ee96c1ce0f13e5fae696e1a4adb021351de046fe
sha256: 433456aea2b9b097b0bf6bc8c16a43416d6d46477c6b510f58835aa775741013
sha512: abed02ea4a9e64b8cbcd6c92f5c2d97903109fdad1f99ad5b3729e813fcd8da63bf110945baf0f3cdc01a00e66fa53f1377a21185418ea388e333a380207dcbb
ssdeep: 6144:NQZXVRBpE3hetT5tBTyTmYokr12Hd1x2Ezp87G9Aen7u91zjTTy+:EVRTE3het1yJh2HduH7GqjTy+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12564CF2231C448E6C58D7633CEA5BB3CE3E9F27898319F775799065C9D3A9408F0627A
sha3_384: db8ea70835e80f5572d978d32b6df24b534d99e5475bc26c876e63f4cbd20a15d3854e68ba1bb4e6a63702445aa5938a
ep_bytes: 558bec6aff6800914100687453410064
timestamp: 2015-11-23 15:47:54

Version Info:

0: [No Data]

Backdoor:Win32/Venik.J also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Palevo.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.15339
ClamAVWin.Dropper.Gh0stRAT-7060943-1
FireEyeGeneric.mg.107f36b0cdd241d0
CAT-QuickHealBackdoor.Venik.25957
ALYacGen:Variant.Doina.15339
Cylanceunsafe
ZillyaAdware.Eorezo.Win32.21038
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Palevo.85c7a051
K7GWTrojan ( 0055e3e41 )
K7AntiVirusTrojan ( 0055e3e41 )
ArcabitTrojan.Doina.D3BEB
VirITBackdoor.Win32.Generic.NAS
CyrenW32/Palevo.AH.gen!Eldorado
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Farfli.BWM
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Palevo.hyhq
BitDefenderGen:Variant.Doina.15339
NANO-AntivirusTrojan.Win32.Dwn.dyxvpz
AvastWin32:BackdoorX-gen [Trj]
TencentP2P-Worm.Win32.Palevo.pg
EmsisoftGen:Variant.Doina.15339 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader17.51988
VIPREGen:Variant.Doina.15339
TrendMicroTROJ_GEN.R002C0CEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.moderate.ml.score
SophosTroj/Venik-V
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.fzuq
AviraTR/Dropper.Gen
Antiy-AVLWorm[P2P]/Win32.Palevo
MicrosoftBackdoor:Win32/Venik.J
ViRobotTrojan.Win32.U.Agent.302592
ZoneAlarmP2P-Worm.Win32.Palevo.hyhq
GDataWin32.Trojan.Palevo.E
GoogleDetected
AhnLab-V3Dropper/Win.Banki.R531254
McAfeeBackDoor-FDAJ!107F36B0CDD2
MAXmalware (ai score=83)
VBA32TrojanPSW.WOW
MalwarebytesMalware.AI.1613291764
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CEL23
RisingBackdoor.Venik!8.11E (TFE:5:RqOiOODmXTB)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Farfli.BTY!tr
BitDefenderThetaGen:NN.ZexaF.36196.sqX@a8AC!Mmb
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Venik.J?

Backdoor:Win32/Venik.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment