Malware

Win32/Sednit.DV malicious file

Malware Removal

The Win32/Sednit.DV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Sednit.DV virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

www.xbhp.com
www.c4csa.org

How to determine Win32/Sednit.DV?


File Info:

crc32: 55C0A7A0
md5: df6c6ee05898ce35ce5963ff0ae2344d
name: DF6C6EE05898CE35CE5963FF0AE2344D.mlw
sha1: afbdb13d8f620d0a5599cbc7a7d9ce8001ee32f1
sha256: ee7cfc55a49b2e9825a393a94b0baad18ef5bfced67531382e572ef8a9ecda4b
sha512: cffb9bf377c98f8def646fb36f58e006d5d526867e7313585f124747276d8fdcc41a54ca34ec23174fd0463a31870a5679772e587cb6827a0ff1c99e46abd894
ssdeep: 49152:AWwCcEF34wr2IRQSOpRtNGlHgTenh3ny:NKE+wA6Xnh3y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProgramID: com.embarcadero.Windows Start-Up Application
ProductName: Windows Start-Up Application
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription: Windows Start-Up Application
Translation: 0x0409 0x04e4

Win32/Sednit.DV also known as:

DrWebTrojan.AgentSpy.31
MicroWorld-eScanTrojan.GenericKD.45745429
McAfeeArtemis!DF6C6EE05898
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780a61 )
BitDefenderTrojan.GenericKD.45745429
K7GWTrojan ( 005780a61 )
ArcabitTrojan.Generic.D2BA0515
BitDefenderThetaGen:NN.ZexaF.34574.BN0@aS!0Avii
CyrenW32/Trojan.NQBY-4344
SymantecML.Attribute.HighConfidence
KasperskyTrojan.Win32.Agentb.kjiz
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareTrojan.GenericKD.45745429
SophosMal/Generic-S + Troj/Keylog-ANH
ComodoMalware@#1h20yp3netv4x
F-SecureTrojan.TR/Sednit.dhtfi
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeTrojan.GenericKD.45745429
EmsisoftTrojan.GenericKD.45745429 (B)
IkarusTrojan.Win32.Agent
AviraTR/Sednit.dhtfi
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftExploit:Win32/ShellCode!ml
ViRobotTrojan.Win32.Z.Agent.3603456.C
ZoneAlarmTrojan.Win32.Agentb.kjiz
GDataTrojan.GenericKD.45745429
CynetMalicious (score: 85)
ALYacTrojan.Agent.Sednit
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
ESET-NOD32a variant of Win32/Sednit.DV
TencentWin32.Trojan.Agentb.Wuhg
FortinetW32/Agent.ABCX!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.Agentb.HgIASPUA

How to remove Win32/Sednit.DV?

Win32/Sednit.DV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment