Malware

What is “ML/PE-A + Troj/Rozena-D”?

Malware Removal

The ML/PE-A + Troj/Rozena-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Rozena-D virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Rozena-D?


File Info:

crc32: BA26A205
md5: 9859d9e45e4235f11dfc11302cee08d0
name: 9859D9E45E4235F11DFC11302CEE08D0.mlw
sha1: 368a102171a2d267d7aa59bb132fe18b699c9533
sha256: 8bf3e0441965e18c124608933c7db59436a2a4c3a8eb8fac1924269a60c325bd
sha512: f80a6435822e60b32c36e2de0181f80e6d40a3d73e46f1048bdd36806d5f7dd1f943c869c3145a206356ec97705c3071cd7d7b5c60583400c44143c1aa5b810e
ssdeep: 96:QicbQfgtZyNmx1jMLZm9pE+ymLADBTgut+waBWf8i2qIraqQ3rqxsyX0l:ncb/rfD962LADxgE+wa4f8iqbI/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x007f 0x04b0
LegalCopyright:
InternalName: test
FileVersion: 0.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion:
FileDescription:
OriginalFilename: test.exe

ML/PE-A + Troj/Rozena-D also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36093865
FireEyeGeneric.mg.9859d9e45e4235f1
CAT-QuickHealTrojan.Generic
McAfeeTrojan-Veil-FOJU!9859D9E45E42
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 004b595d1 )
BitDefenderTrojan.GenericKD.36093865
K7GWTrojan-Downloader ( 004b595d1 )
Cybereasonmalicious.171a2d
BitDefenderThetaGen:NN.ZemsilF.34804.am0@a0R5LNk
SymantecBackdoor.Veilev
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Generic.460f3552
NANO-AntivirusTrojan.Win32.Kazy.dkjuiw
ViRobotTrojan.Win32.Z.Wacatac.8192.CS
TencentWin32.Trojan.Generic.Htlx
Ad-AwareTrojan.GenericKD.36093865
EmsisoftTrojan.GenericKD.36093865 (B)
ComodoMalware@#1lv9vu8o9mpbu
F-SecureHeuristic.HEUR/AGEN.1107306
TrendMicroTROJ_GEN.R002C0OAC21
McAfee-GW-EditionTrojan-Veil-FOJU!9859D9E45E42
SophosML/PE-A + Troj/Rozena-D
IkarusTrojan-Downloader.MSIL.Tiny
AviraHEUR/AGEN.1107306
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.Generic.D226BFA9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.36093865
CynetMalicious (score: 100)
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.36093865
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.SM
TrendMicro-HouseCallTROJ_GEN.R002C0OAC21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetW32/Generic.D!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM03.0.9087.Malware.Gen

How to remove ML/PE-A + Troj/Rozena-D?

ML/PE-A + Troj/Rozena-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment