Malware

About “Generic.RozenaA.C12C294B” infection

Malware Removal

The Generic.RozenaA.C12C294B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.RozenaA.C12C294B virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking

How to determine Generic.RozenaA.C12C294B?


File Info:

crc32: 3ED3D6B4
md5: 91bdbd16f632634c2ae8c932d5e74105
name: 91BDBD16F632634C2AE8C932D5E74105.mlw
sha1: af8271e45c79211756ce294d59e2e48ced1eff62
sha256: c7613ab738b8ca85cd452684fe23932046ea0549e116729917be00fa8dc2bd60
sha512: 963aa9b8992f49fcbba13a6f0134f003d9d95241e9d8d329ed1c98999c495db99d0de505d7a490b2763fdaaae501598f6309c23282b7d1c762751528c2e06220
ssdeep: 48:qFGFzmems3JaUk+sEG1tvEkOPkyvjVKXysWRLU52XCHbSeJY8JTaFI7h:eGFzme13vHsEgezKiPRLUMSHh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.RozenaA.C12C294B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.41928
CynetMalicious (score: 85)
ALYacDeepScan:Generic.RozenaA.C12C294B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004b76a21 )
K7AntiVirusTrojan ( 004b76a21 )
BaiduWin32.Trojan.Kryptik.sv
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Inject.NJV
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Exploit.Call4_Dword_Xor-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.RozenaA.C12C294B
MicroWorld-eScanDeepScan:Generic.RozenaA.C12C294B
Ad-AwareDeepScan:Generic.RozenaA.C12C294B
SophosML/PE-A + ATK/Veil-AA
F-SecureTrojan.TR/Hijacker.Gen
BitDefenderThetaGen:NN.ZedlaF.34670.amOfaekNYJi
TrendMicroTROJ_SWRORT.SMDSA
McAfee-GW-EditionGenericRXEI-BI!592B6F9BCEF3
FireEyeGeneric.mg.91bdbd16f632634c
EmsisoftDeepScan:Generic.RozenaA.C12C294B (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.aahy
AviraTR/Hijacker.Gen
MicrosoftTrojan:Win32/Meterpreter.A
ArcabitDeepScan:Generic.RozenaA.C12C294B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.RozenaA.C12C294B
AhnLab-V3Malware/Win32.Generic.C1933244
McAfeeArtemis!91BDBD16F632
MAXmalware (ai score=84)
VBA32TrojanDropper.Injector
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SWRORT.SMDSA
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazpDTx8Yd8AOSfaqwBJ3WfOy)
YandexTrojan.GenAsa!cEKcC3j8Bqk
IkarusTrojan.Win32.Swrort
FortinetW32/Kryptik.DALA!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM31.1.6367.Malware.Gen

How to remove Generic.RozenaA.C12C294B?

Generic.RozenaA.C12C294B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment