Backdoor

Backdoor.Rozena (file analysis)

Malware Removal

The Backdoor.Rozena is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor.Rozena virus can do?

  • Anomalous binary characteristics

How to determine Backdoor.Rozena?


File Info:

crc32: 03276ECA
md5: 45aea67dcd84c72bccf5a8a4c66fa8e4
name: winhlp32.exe
sha1: b1d5a362025e4400be8971e277a89dda3a47dc34
sha256: b94f1103e5fbe594329eb82f30be901437d35ac4188f1fc2f8f2e83d82faad69
sha512: 7999f3b0b997dc616bbe2e3b0abaf52abb1f994165f206b27860d97848332b53189523922fdbdb8e9e48ee30358b41ec0f3d41b641aa17070ac508951b5bb078
ssdeep: 6144:aRGlyFiARTkcr4rcFgZ/uJpYhMdKBx34Yd:aYPukUgZWJihMQ
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Backdoor.Rozena also known as:

MicroWorld-eScanGen:Variant.Symmi.93915
FireEyeGeneric.mg.45aea67dcd84c72b
ALYacGen:Variant.Symmi.93915
MalwarebytesBackdoor.Rozena
BitDefenderGen:Variant.Symmi.93915
Cybereasonmalicious.dcd84c
Invinceaheuristic
BitDefenderThetaGen:Trojan.Heur.JP.rCW@aiem41l
F-ProtW32/Diple.F.gen!Eldorado
SymantecBackdoor.Cobalt
TrendMicro-HouseCallTrojan.Win32.COBALT.SM
GDataGen:Variant.Symmi.93915
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Rozena.faqakq
ViRobotTrojan.Win32.Agent.284672.R
RisingBackdoor.Meterpreter!1.B96B (CLASSIC)
Endgamemalicious (high confidence)
SophosTroj/Swrort-BT
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebBackDoor.Meterpreter.92
TrendMicroTrojan.Win32.COBALT.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Fugrafa.858 (B)
APEXMalicious
CyrenW32/Diple.F.gen!Eldorado
JiangminTrojan.Generic.ccimf
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen7
ArcabitTrojan.Symmi.D16EDB
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Swrort!rfn
AhnLab-V3Trojan/Win32.Dynamer.C1321589
Acronissuspicious
VBA32Trojan.Swrort
MAXmalware (ai score=81)
Ad-AwareGen:Variant.Symmi.93915
CylanceUnsafe
ESET-NOD32a variant of Win32/Rozena.SA
IkarusTrojan.Win32.Rozena
FortinetW32/Generic.AC.416F47
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.6E01.Malware.Gen

How to remove Backdoor.Rozena?

Backdoor.Rozena removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment