Malware

What is “Win32/Rozena.ACP”?

Malware Removal

The Win32/Rozena.ACP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.ACP virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Rozena.ACP?


File Info:

crc32: 2F09743C
md5: 53383513ced806cf2869667cc9e1e5a1
name: 53383513CED806CF2869667CC9E1E5A1.mlw
sha1: efc70f387ae03d20ff45e5ed37cf4fb974dd0d1d
sha256: 097c0a5fe03f67c246e85e20b16b85555788017bbed7d71841c2e52196be25d2
sha512: 93809f1f1a0500d7c313405622318375332b7c80f47b2c8c5a734c63914d223bc2173c3b9e6beda316a4bd3c11ea53d80512c0266605cea02ae219d1dc8becc5
ssdeep: 49152:0Xz+ZNjdQ16kF443oB4kRlekygAiNSpil0+Ogz496HvEoHMLb:0Xz+vpr0NomxmHMoSjgzwkfsf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Mojang
FileDescription: Minecraft 1.5 Installation
FileVersion: 1.5
Comments:
CompanyName: Mojang
Translation: 0x0409 0x04e4

Win32/Rozena.ACP also known as:

BkavW32.FamVT.EqtoneGR.Trojan
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.MulDrop10.16759
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.41301105
CylanceUnsafe
SangforTrojan.Win32.Occamy.C09
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanDropper:Win32/Dapato.b1605594
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3ced80
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.ACP
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Dropper.Win32.Dapato.plub
BitDefenderTrojan.GenericKD.41301105
NANO-AntivirusTrojan.Win32.Phave.frzqfu
MicroWorld-eScanTrojan.GenericKD.41301105
TencentWin32.Trojan-dropper.Dapato.Stam
SophosMal/Generic-R
ComodoMalware@#1ay3r9r19wy3b
BitDefenderThetaGen:NN.ZexaF.34770.QCW@a4SLjPk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.53383513ced806cf
EmsisoftTrojan.GenericKD.41301105 (B)
JiangminTrojanDropper.Dapato.zap
AviraTR/Drop.Dapato.fyzoq
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Occamy.C09
ArcabitTrojan.Generic.D2763471
AegisLabTrojan.Win32.Dapato.4!c
ZoneAlarmTrojan-Dropper.Win32.Dapato.plub
GDataTrojan.GenericKD.41301105
AhnLab-V3Malware/Gen.Generic.C3002118
McAfeeArtemis!53383513CED8
MAXmalware (ai score=99)
VBA32TrojanDropper.Dapato
PandaTrj/CI.A
IkarusGen.Heur
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Dapato.PLUB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dapato.HgIASOYA

How to remove Win32/Rozena.ACP?

Win32/Rozena.ACP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment