Backdoor

Should I remove “Backdoor:Win32/Venik.S!bit”?

Malware Removal

The Backdoor:Win32/Venik.S!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Venik.S!bit virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
xred.mooo.com
a.tomx.xyz
freedns.afraid.org
users.qzone.qq.com

How to determine Backdoor:Win32/Venik.S!bit?


File Info:

crc32: 4ADBC2F3
md5: 12698681ebc08747115c885ed4d3787f
name: dnf.exe
sha1: 5857d0c73aead48b7b804215eb2a737e9ce6d678
sha256: e3a74897f8d705b8d33c3ebdfc123184d4543dcfc1e66704c5508edf8ae9f2df
sha512: 08c3a45d695a87facaf776d057f22f4071e4f0af32e4143a6c5fc5503e5d5491865a174d43c982ea822c6664d0595dbbe9133fc278259b4e6646c97e4eb6f17e
ssdeep: 12288:5MSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9qv6Akoxj:5nsJ39LyjbJkQFMhmC+6GD9lq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Backdoor:Win32/Venik.S!bit also known as:

MicroWorld-eScanDropped:Generic.ZegostB.A07965D8
FireEyeGeneric.mg.12698681ebc08747
CAT-QuickHealSus.Nocivo.E0011
Qihoo-360HEUR/QVM41.1.4D57.Malware.Gen
McAfeeGenericRXCB-VC!12698681EBC0
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Generic.ZegostB.A07965D8
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1ebc08
Invinceaheuristic
BitDefenderThetaAI:Packer.F5AF03D517
F-ProtW32/Zorex.A
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
ClamAVWin.Trojan.Generic-6305873-0
GDataDropped:Generic.ZegostB.A07965D8
KasperskyBackdoor.Win32.DarkKomet.hqxy
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
AvastWin32:Farfli-CD [Trj]
TencentMalware.Win32.Gencirc.10b8ace3
Ad-AwareDropped:Generic.ZegostB.A07965D8
SophosMal/Behav-001
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
DrWebTrojan.DownLoader22.9658
ZillyaTrojan.Delf.Win32.76144
TrendMicroVirus.Win32.NAPWHICH.B
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
Trapminesuspicious.low.ml.score
EmsisoftDropped:Generic.ZegostB.A07965D8 (B)
APEXMalicious
CyrenW32/Backdoor.OAZM-5661
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitHEUR.VBA.Trojan.d
SUPERAntiSpywareAdware.FileTour/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
MicrosoftBackdoor:Win32/Venik.S!bit
SentinelOneDFI – Malicious PE
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
VBA32BScope.Backdoor.DarkKomet
ALYacDropped:Generic.ZegostB.A07965D8
MalwarebytesTrojan.Agent
ESET-NOD32Win32/Delf.NBX
RisingBackdoor.Agent!1.BF3D (CLASSIC)
YandexBackDoor.Optix!
IkarusTrojan-PWS.Win32.QQPass
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.NBX!tr
AVGWin32:Farfli-CD [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor:Win32/Venik.S!bit?

Backdoor:Win32/Venik.S!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment