Malware

PowerShell/Rozena.BI removal tips

Malware Removal

The PowerShell/Rozena.BI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/Rozena.BI virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine PowerShell/Rozena.BI?


File Info:

name: 080B30B0144C707D8E6B.mlw
path: /opt/CAPEv2/storage/binaries/ac203285e59d6434602abb8b67e655d52a4b68067169353de756c2efa2a75539
crc32: 76C59A91
md5: 080b30b0144c707d8e6bcf7f6a4172a9
sha1: 0c5bb73ac5d3d97c08b82c9cecfbfff726dd76c7
sha256: ac203285e59d6434602abb8b67e655d52a4b68067169353de756c2efa2a75539
sha512: e356f0e67fb3f5be02a7f25db7bab2afb26baec1ba1fab0d468ef508746d98b9d432231c6aaa8610f23d95c97c29148ddc120cdc3019942cd524d329e0c0af32
ssdeep: 24:etGSmMZWCg8k78uRSrCx8m3VgUHIwCnXIJKNkFtkZfJOdWI+ycuZhNlPakSSoPNq:6/JgcbGx8oyBwmNywJJP1ullPa3SQq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T175710E1693E84667E0AB07316EF3432767B0F8509B77932E5981022DBCA17B01A71BB0
sha3_384: 37e61d5e02f39cd6ae905ed3978b83f5532383dbd2829abb85ed97990320c3fefc2b258bf0306d3aaf16443e92498c98
ep_bytes: ff250020001000000000000000000000
timestamp: 2023-03-16 02:15:51

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: bvo5am50.dll
LegalCopyright:
OriginalFilename: bvo5am50.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

PowerShell/Rozena.BI also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Rozena.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Infected.zz
McAfeeArtemis!080B30B0144C
Cylanceunsafe
ZillyaTrojan.Rozena.Script.3721
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005270101 )
AlibabaTrojan:MSIL/Rozena.766bcbd8
K7GWTrojan ( 005270101 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of PowerShell/Rozena.BI
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Rozena.gen
AvastWin32:TrojanX-gen [Trj]
F-SecureTrojan.TR/Rozena.Gen
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/Rozena.DS.gen!Eldorado
AviraTR/Rozena.Gen
Antiy-AVLTrojan/PowerShell.Rozena
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Rozena.gen
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5057373
Acronissuspicious
TencentMsil.Trojan.Rozena.Timw
IkarusTrojan.PowerShell.Rozena
MaxSecureTrojan.Malware.115739514.susgen
FortinetMSIL/GenericKDZ.68387!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD

How to remove PowerShell/Rozena.BI?

PowerShell/Rozena.BI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment