Remove Varenyky Trojan (Spambot) and Stop Sextortion

Remove Varenyky Trojan (Spambot) and Stop Sextortion

Update September 2019.
Varenyky is a dangerous Trojan with spyware functionalities which also operates as a spambot. Security researchers believe that the Varenyky spambot is currently under heavy development meaning that it is going to evolve. At the heart of the Varenyky spambot operation is sextortion. The Trojan is designed to steal passwords, and spy on victims’ screen via FFmpeg when they watch adult content.

Varenyky also communicates with its command and control server via Tor, and the spam that activates the operation is sent via email.

Threat Summary

TypeTrojan, Spambot
Short DescriptionVarenyky is a Trojan and a spambot that is currently distributed via phishing and spam emails.
SymptomsThe victims may not experience any apparent symptoms of infection.
Distribution MethodSpam emails and phishing.
Detection Tool See If Your System Has Been Affected by Varenyky


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Varenyky.

Varenyky Trojan and Spambot – Distribution Methods

According to WeLiveSecurity researchers, the Varenyky Trojan is currently targeting France, and more specifically, the users of Orange S.A., a French ISP. The main distribution channel of the spambot is phishing emails. The researchers came across a spam campaign that redirected to a survey and a bogus smartphone promotion. However, another campaign is relying on sextortion principles, and is spying on the victim’s screen while they are visiting adult websites.

One of the malicious documents that is distributing Varenyky is attached in an email states that a bill of €491.27 is available. Upon opening the supposed bill, the victim will be notified that the document is protected by Microsoft Word and needs human verification. In other words, the victim is prompted to enable macros.

It is curious to note that the macro detected in this Word document is using the function Application.LanguageSettings.LanguageID() to obtain the language ID of the victim’s computer.

This ID contains the country and the language set by the user. The script checks if the value returned is 1036 in decimal (or 0x40C in hexadecimal) and according to the Microsoft documentation this value corresponds to France and the French language,” WeLiveSecurity researchers explained.

Related: 4 Reasons Why You Receive Sextortion and Other Email Scams

Varenyky Trojan – Technical Overview

As already mentioned, the Varenyky Trojan is currently targeting French victims via fake invoices in the form of Microsoft Word documents that prompt them to enable macros. When the potential victim opens the document and the macro is executed, the operation makes sure that the user is indeed French. If the victim is of other nationality, the malware operation ceases. If the French origin is confirmed, the malware will communicate with its command and control server to determine what components to download. Varenyky also installs a piece of software that steals passwords and spies on victims via FFmpeg when they are watching pornographic content online.

The Varenyky Trojan can also detect specific “trigger” keywords of sexual nature as well as websites (such as YouPorn, PornHub, and Brazzers. When any of these keywords is caught, the malware will record the computer’s screen via an FFmpeg executable. The recorded content is then sent to the command and control server. Obviously, the reason for recording the victim’s screen under these specific circumstances is sextortion and blackmail. It is also highly possible that Varenyky will be used in highly targeted campaigns.

Remove Varenyky Trojan

If your computer system got infected with the Varenyky Trojan, you should have a bit of experience in removing malware. You should get rid of this Trojan as quickly as possible before it gets the chance to spread further and infect other computers. Consider removing the Trojan immediately, and follow the step-by-step instructions available below.

Note! Your computer system may be affected by Varenyky and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of Varenyky.
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove Varenyky follow these steps:

1. Boot Your PC In Safe Mode to isolate and remove Varenyky files and objects

Boot Your PC Into Safe Mode

1. For Windows XP, Vista and 7. 2. For Windows 8, 8.1 and 10. Fix registry entries created by malware and PUPs on your PC.

For Windows XP, Vista and 7 systems:

1. Remove all CDs and DVDs, and then Restart your PC from the “Start” menu.
2. Select one of the two options provided below:

For PCs with a single operating system: Press “F8” repeatedly after the first boot screen shows up during the restart of your computer. In case the Windows logo appears on the screen, you have to repeat the same task again.


For PCs with multiple operating systems: Тhe arrow keys will help you select the operating system you prefer to start in Safe Mode. Press “F8” just as described for a single operating system.


3. As the “Advanced Boot Options” screen appears, select the Safe Mode option you want using the arrow keys. As you make your selection, press “Enter“.

4. Log on to your computer using your administrator account


While your computer is in Safe Mode, the words “Safe Mode” will appear in all four corners of your screen.

Step 1: Open up the Start Menu.

Step 2: Click on the Power button (for Windows 8 it is the little arrow next to the “Shut Down” button) and whilst holding down “Shift” click on Restart.

Windows 8 Safe Mode Step 2 Shift Restart 2018

Step 3: After reboot, a blue menu with options will appear. From them you should choose Troubleshoot.

Windows 8 10 Safe Mode Boot Options Step 3 Choose an option 2018

Step 4: You will see the Troubleshoot menu. From this menu choose Advanced Options.

Windows 8 10 Safe Mode Boot Options Step 4 Troubleshoot 2018

Step 5: After the Advanced Options menu appears, click on Startup Settings.

Windows 8 10 Safe Mode Boot Options Step 5 Advanced 2018

Step 6: From the Startup Settings menu, click on Restart.

Windows 8 10 Safe Mode Boot Options Step 6 Startup Settings Restart 2018

Step 7: A menu will appear upon reboot. You can choose any of the three Safe Mode options by pressing its corresponding number and the machine will restart.

Windows 8 10 Safe Mode Boot Options Step 7 Safe Modes 2018

Some malicious scripts may modify the registry entries on your computer to change different settings. This is why cleaning your Windows Registry Database is recommended. Since the tutorial on how to do this is a bit long and tampering with registries could damage your computer if not done properly you should refer and follow our instructive article about fixing registry entries, especially if you are unexperienced in that area.

2. Find files created by Varenyky on your PC

Find files created by Varenyky

1. For Windows 8, 8.1 and 10. 2. For Windows XP, Vista, and 7.

For Newer Windows Operating Systems

Step 1:

On your keyboard press + R and write explorer.exe in the Run text box and then click on the Ok button.


Step 2:

Click on your PC from the quick access bar. This is usually an icon with a monitor and its name is either “My Computer”, “My PC” or “This PC” or whatever you have named it.


Step 3:

Navigate to the search box in the top-right of your PC’s screen and type “fileextension:” and after which type the file extension. If you are looking for malicious executables, an example may be “fileextension:exe”. After doing that, leave a space and type the file name you believe the malware has created. Here is how it may appear if your file has been found:

N.B. We recommend to wait for the green loading bar in the navination box to fill up in case the PC is looking for the file and hasn’t found it yet.

For Older Windows Operating Systems

In older Windows OS’s the conventional approach should be the effective one:

Step 1:

Click on the Start Menu icon (usually on your bottom-left) and then choose the Search preference.


Step 2:

After the search window appears, choose More Advanced Options from the search assistant box. Another way is by clicking on All Files and Folders.

search companion

Step 3:

After that type the name of the file you are looking for and click on the Search button. This might take some time after which results will appear. If you have found the malicious file, you may copy or open its location by right-clicking on it.

Now you should be able to discover any file on Windows as long as it is on your hard drive and is not concealed via special software.

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool

Scan your PC and Remove Varenyky with SpyHunter Anti-Malware Tool and back up your data

1. Install SpyHunter to scan for Varenyky and remove them.2. Scan with SpyHunter, Detect and Remove Varenyky. Back up your data to secure it from malware in the future.
Step 1: Click on the “Download” button to proceed to SpyHunter’s download page.

It is recommended to run a scan before purchasing the full version of the software to make sure that the current version of the malware can be detected by SpyHunter. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

Step 2: Guide yourself by the download instructions provided for each browser.

Step 3: After you have installed SpyHunter, wait for it to update automatically.


Step 1: After the update process has finished, click on the ‘Malware/PC Scan’ tab. A new window will appear. Click on ‘Start Scan’.


Step 2: After SpyHunter has finished scanning your PC for any files of the associated threat and found them, you can try to get them removed automatically and permanently by clicking on the ‘Next’ button.


Step 3: If any threats have been removed, it is highly recommended to restart your PC.

Back up your data to secure it against attacks in the future

IMPORTANT! Before reading the Windows backup instructions, we highly recommend to back up your data with a cloud backup solution and insure your files against any type of loss, even from the most severe threats. We recommend you to read more about it and to download SOS Online Backup .


Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum for 4 years. Enjoys ‘Mr. Robot’ and fears ‘1984’. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share