Backdoor

Backdoor:Win32/Venik!rfn (file analysis)

Malware Removal

The Backdoor:Win32/Venik!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Venik!rfn virus can do?

  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself

How to determine Backdoor:Win32/Venik!rfn?


File Info:

crc32: 7428476C
md5: affc65b8aaac703d04def10470c68f34
name: win.exe
sha1: 50c4fddeca2ace35b8138335fe4a9b42a85c9682
sha256: 39d35455fe9c83fda0a482e921884d0872d25ea6885e9c8d3c637e2af7fa7c21
sha512: f59cfa3f695da0bb70f85f7710c6f2e715806c6a0da1d4d96d732352ba15e42d4b42f122ab8a0a81756558a194e98730a48dcf8b8d1238008866df2d663ee51c
ssdeep: 768:sX0mvrQFZiRigW3BeBPkgkqMptgYToDWzblDs:sXBrCGigWxaOmiH9s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Venik!rfn also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen7.25806
MicroWorld-eScanGen:Variant.Ulise.88916
FireEyeGeneric.mg.affc65b8aaac703d
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360HEUR/QVM07.1.516D.Malware.Gen
ALYacGen:Variant.Ulise.88916
CylanceUnsafe
VIPRETrojan.Win32.Redosdru.C (v)
SangforMalware
K7AntiVirusTrojan ( 004b78a51 )
BitDefenderGen:Variant.Ulise.88916
K7GWTrojan ( 004b78a51 )
Cybereasonmalicious.8aaac7
TrendMicroBKDR_ZEGOST.SM37
BitDefenderThetaAI:Packer.B4D7A47F1E
F-ProtW32/Farfli.CY
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Malware.Farfli-7101089-0
GDataGen:Variant.Ulise.88916
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Farfli.a022de98
NANO-AntivirusTrojan.Win32.AD.erhebd
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.10b0cd6d
Ad-AwareGen:Variant.Ulise.88916
EmsisoftGen:Variant.Ulise.88916 (B)
F-SecureHeuristic.HEUR/AGEN.1044595
Invinceaheuristic
McAfee-GW-EditionGenericRXFT-ZL!AFFC65B8AAAC
Trapminemalicious.high.ml.score
SophosMal/Behav-225
IkarusTrojan.Win32.Farfli
CyrenW32/Farfli.OIMS-2324
JiangminTrojan.Generic.beksk
WebrootW32.Malware.gen
AviraHEUR/AGEN.1044595
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D15B54
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Venik!rfn
AhnLab-V3Trojan/Win32.Generic.C2072068
McAfeeGenericRXFT-ZL!AFFC65B8AAAC
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.Cimuz.B
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ZonerTrojan.Win32.86085
ESET-NOD32Win32/Farfli.BLH
TrendMicro-HouseCallBKDR_ZEGOST.SM37
RisingBackdoor.Agent!1.BA39 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Farfli.CMC!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Backdoor:Win32/Venik!rfn?

Backdoor:Win32/Venik!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment