Trojan

Trojan:Win32/Sefnit.Q removal guide

Malware Removal

The Trojan:Win32/Sefnit.Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sefnit.Q virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan:Win32/Sefnit.Q?


File Info:

name: 8F57CC38507EE44D7253.mlw
path: /opt/CAPEv2/storage/binaries/b8a8ade9da08bbb042a2a1cd01e8ab173257eb9f1f82830d77681db46458d141
crc32: DDD4C179
md5: 8f57cc38507ee44d72536cd3db2f7e3d
sha1: 66cb8b5ef3e5c771936bd55f09d631c967d6e4cd
sha256: b8a8ade9da08bbb042a2a1cd01e8ab173257eb9f1f82830d77681db46458d141
sha512: 5bca48e4923c345ac9b17ca65e9cbad20d5e08bb2a1b98e14dcfa91959a06ec3a46280e97025d7f72e9198a78ba341dc09f93516cc1449860d8ca7361ac705b2
ssdeep: 196608:ILfO8ALKcKjzrYQ68nNc6VlMfmVjSc63yayhgrcTDkaDmT8E/GsZf4PCZJLcRlC:if7LcKjnYQRnNJVlMfmV6cfkbYIjN4kX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150A633AA53A03E18C10A597B2C91C7D9887CAD4267602CD5F853DF2049774BEC6F4AEF
sha3_384: af9b5652a4f146be212ea0254bcd88b0fee1f6d94cf1501137a8f9bb92bd549278b51ebd76cbbf8573cb94d8e5193e3e
ep_bytes: 60be15c075008dbeeb4fcaff57eb0b90
timestamp: 2009-02-18 05:39:53

Version Info:

CompanyName: Vrnjqyudtk Qajgudhu
FileDescription: Vrnjqyudtk Ufstxfwn Rpsinxtj
FileVersion: 127, 79, 16, 45
InternalName: Vrnjqyudtk
LegalCopyright: Copyright © Vrnjqyudtk Qajgudhu 1997-2010
OriginalFilename: Vrnjqyudtk.exe
ProductName: Vrnjqyudtk Ufstxfwn Rpsinxtj
ProductVersion: 62, 123, 113, 87
Translation: 0x0409 0x04e4

Trojan:Win32/Sefnit.Q also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.569179
FireEyeGeneric.mg.8f57cc38507ee44d
McAfeeTrojan-FADF!8F57CC38507E
CylanceUnsafe
VIPRETrojan.Win32.Kryptik.mcf (v)
SangforSuspicious.Win32.Razy.569179
AlibabaVirTool:Win32/Obfuscator.57ba6b8e
Cybereasonmalicious.8507ee
BitDefenderThetaGen:NN.ZexaF.34212.@pNfa0xghZjc
CyrenW32/Zbot.CN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LPD
TrendMicro-HouseCallBKDR_QAKBOT.SMG
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-13636
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.569179
NANO-AntivirusTrojan.Win32.Zbot.crbccp
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Rn]
AvastWin32:Kryptik-AQX [Trj]
TencentMalware.Win32.Gencirc.10b87a7a
Ad-AwareGen:Variant.Razy.569179
EmsisoftGen:Variant.Razy.569179 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
ZillyaTrojan.FakeAV.Win32.51063
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionTrojan-FADF!8F57CC38507E
SophosMal/Generic-S + Mal/FakeAV-IU
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.aynv
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.1AA0C2
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Sefnit.Q
ViRobotTrojan.Win32.A.Zbot.1482752[UPX]
GDataGen:Variant.Razy.569179
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Zbot.R5479
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Razy.569179
MalwarebytesMalware.AI.2520509789
APEXMalicious
RisingTrojan.Sefnit!8.B5B (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.NAS!tr
AVGWin32:Kryptik-AQX [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Sefnit.Q?

Trojan:Win32/Sefnit.Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment