Backdoor

About “Backdoor:Win32/Venik” infection

Malware Removal

The Backdoor:Win32/Venik is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Venik virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Backdoor:Win32/Venik?


File Info:

crc32: 975C5EA8
md5: 1ed2122670b21b06c8e85ff984c96606
name: 1ED2122670B21B06C8E85FF984C96606.mlw
sha1: 401793ac6011e12da73a6a70ec1f7544fe8bfdb3
sha256: da72613a5622d4c7ac4c9e74c0eee59d1982d68490dbe0a48ebe0044e1d9eb0a
sha512: 1119e9198cf216f736176d4e9154ad2994989652fce7b78006f81a60b3c00dbb59ba5ec74dc8bb75226709c101c8bc7922bce0f5c008f117dec1ad543ade276c
ssdeep: 384:tfuPb0HzJw4a0UkqAV4fXt2C849tFrbUiR/7FxObMBPB70gajTcKF3Vh0:IoTJw4a0R5+MC849tnxY5TFg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Venik also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 004b78a51 )
DrWebTrojan.DownLoader26.35525
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.ZegostB.2AAB58D1
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.35801
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Venik.49adc6a9
K7GWTrojan ( 004b78a51 )
Cybereasonmalicious.670b21
TrendMicroBKDR_ZEGOST.SM37
CyrenW32/S-3daeeeba!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.BLH
ZonerTrojan.Win32.86668
APEXMalicious
TotalDefenseWin32/PackedBaidu
AvastWin32:Dh-A [Heur]
ClamAVWin.Trojan.Generic-6305873-0
GDataGeneric.ZegostB.2AAB58D1
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGeneric.ZegostB.2AAB58D1
NANO-AntivirusTrojan.Win32.Farfli.fabycr
ViRobotTrojan.Win32.Z.Farfli.22528.N
MicroWorld-eScanGeneric.ZegostB.2AAB58D1
TencentMalware.Win32.Gencirc.10b3a9b9
Ad-AwareGeneric.ZegostB.2AAB58D1
SophosMal/Behav-024
ComodoTrojWare.Win32.GameThief.Magania.~NWABU@18g2sq
F-SecureTrojan.TR/Spy.Gen
BitDefenderThetaAI:Packer.681E25251E
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1ed2122670b21b06
EmsisoftGeneric.ZegostB.2AAB58D1 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/QQhelper.C.gen!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Worm.Gen
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Backdoor]/Win32.AGeneric
MicrosoftBackdoor:Win32/Venik
JiangminTrojan.Vehidis.jf
ArcabitGeneric.ZegostB.2AAB58D1
ZoneAlarmHEUR:Backdoor.Win32.Generic
TACHYONTrojan/W32.Agent.43520.ACK
AhnLab-V3Trojan/Win32.RL_AutoRun.R263968
Acronissuspicious
McAfeeGenericRXAA-AA!1ED2122670B2
MAXmalware (ai score=85)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Dropper.UPX
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM37
RisingBackdoor.Farfli!1.64B3 (CLOUD)
IkarusBackdoor.Win32.Venik
MaxSecureTrojan.Malware.7175197.susgen
FortinetW32/Farfli.BLH!tr
AVGWin32:Dh-A [Heur]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.d55

How to remove Backdoor:Win32/Venik?

Backdoor:Win32/Venik removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment