Malware

Dropped:Generic.RozenaA.AA0CFFC4 removal instruction

Malware Removal

The Dropped:Generic.RozenaA.AA0CFFC4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.RozenaA.AA0CFFC4 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

xred.mooo.com
freedns.afraid.org
ocsp.pki.goog

How to determine Dropped:Generic.RozenaA.AA0CFFC4?


File Info:

crc32: B2883C4B
md5: 3f749590b51e6aeb5319ac1baece7be0
name: 3F749590B51E6AEB5319AC1BAECE7BE0.mlw
sha1: 6a59f362b204040a9a392ec5670b33bf2e492705
sha256: 3c58a233a55551ebf5d83a05fa9b9bf34decc599e6fcdb6418cc7d1feb7c5fdc
sha512: 578f95bf6b43334f68fe8b39971ce7aacee532a3956250f4b762eca7b9710b4f4e9aa073c24080723b8c879fc7078784275bd2637c9c35fbea2ca069cdf1088b
ssdeep: 12288:BMSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9eUwyL4G6wo0:BnsJ39LyjbJkQFMhmC+6GD9lwjHwX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Dropped:Generic.RozenaA.AA0CFFC4 also known as:

BkavW32.FamVT.GaionLTK.Trojan
K7AntiVirusTrojan ( 000112511 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.9658
CynetMalicious (score: 100)
CAT-QuickHealSus.Nocivo.E0011
ALYacDropped:Generic.RozenaA.AA0CFFC4
CylanceUnsafe
ZillyaTrojan.Delf.Win32.76144
SangforWin.Malware.Delf-6899401-0
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 000112511 )
Cybereasonmalicious.0b51e6
CyrenW32/Backdoor.OAZM-5661
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.NBX
ZonerTrojan.Win32.88102
APEXMalicious
AvastWin32:SwPatch [Wrm]
ClamAVWin.Trojan.MSShellcode-7
KasperskyBackdoor.Win32.DarkKomet.hqxy
BitDefenderDropped:Generic.RozenaA.AA0CFFC4
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
ViRobotWin32.Zorex.A
SUPERAntiSpywareAdware.FileTour/Variant
MicroWorld-eScanDropped:Generic.RozenaA.AA0CFFC4
TencentVirus.Win32.DarkKomet.a
Ad-AwareDropped:Generic.RozenaA.AA0CFFC4
SophosTroj/DocDl-JJH
ComodoVirus.Win32.Agent.DE@74b38h
BitDefenderThetaAI:Packer.F5AF03D517
VIPREBehavesLike.Win32.Malware.eah (mx-v)
TrendMicroVirus.Win32.NAPWHICH.B
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.3f749590b51e6aeb
EmsisoftDropped:Generic.RozenaA.AA0CFFC4 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Synaptics.Gen
WebrootW32.Malware.gen
AviraTR/Patched.Gen2
eGambitUnsafe.AI_Score_100%
MicrosoftWorm:Win32/AutoRun!atmn
GridinsoftMalware.Win32.Gen.sm!s1
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
GDataWin32.Backdoor.Agent.AXS
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
McAfeeFileTour
MAXmalware (ai score=83)
VBA32TScope.Trojan.Delf
MalwarebytesLamer.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqzmsP7GbOG59wD97O6HKkp)
YandexTrojan.GenAsa!ETONJRQzPLk
IkarusTrojan-Downloader.VBA.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.NBX!tr
AVGWin32:SwPatch [Wrm]

How to remove Dropped:Generic.RozenaA.AA0CFFC4?

Dropped:Generic.RozenaA.AA0CFFC4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment