Malware

What is “Python/Rozena.CY”?

Malware Removal

The Python/Rozena.CY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Rozena.CY virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Python/Rozena.CY?


File Info:

name: CE08349BDBC15EA636A5.mlw
path: /opt/CAPEv2/storage/binaries/0be1b4366dfcf52c0e3a7427bd2ddf2a9960f07570952c0caf42e43a67cdc249
crc32: 8F0EC6F0
md5: ce08349bdbc15ea636a5659de5d67fd8
sha1: 9d9611cddd1dab93a6b5d9e22be07111a38221a8
sha256: 0be1b4366dfcf52c0e3a7427bd2ddf2a9960f07570952c0caf42e43a67cdc249
sha512: db07c731ae2344950879439a3d2443ce9d2140f2c7b3a58cd110b4cc0f8848a2351cc7296c096e59abc64aaf9bebe25a4e8e06089c1029072300dcd48f43af27
ssdeep: 98304:iB2WqzfwKTDbdRGQSxUTZeNEiIK176XwgqmjkGTL9d5FP3hl4+IIQe:lWqL7TDp4QeUpg176XwgqmNv75hRg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189563374A480D431E472C83886F6EB39753FB0618F24986F97A82B794C326D1677792F
sha3_384: 690db6c02ad3439bb9e3fd9de212e66169bb6976b9c7b686f65427498bef6121d187f75088cdd9f8b9f594664f428eff
ep_bytes: e819050000e98efeffffcccccc575653
timestamp: 2019-07-09 14:23:33

Version Info:

0: [No Data]

Python/Rozena.CY also known as:

BkavW32.Common.E2AC7E95
LionicTrojan.Win32.Blocker.tq1S
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.70068126
FireEyeGeneric.mg.ce08349bdbc15ea6
SkyhighBehavesLike.Win32.BadFile.vc
McAfeeArtemis!CE08349BDBC1
MalwarebytesTrojan.Rozena.Python
VIPRETrojan.GenericKD.70068126
SangforTrojan.Python.Rozena.Vr48
K7AntiVirusTrojan ( 0057f6ea1 )
BitDefenderTrojan.GenericKD.70068126
K7GWTrojan ( 0057f6ea1 )
BitDefenderThetaGen:NN.ZexaF.36792.@BZ@ai3cEjc
SymantecTrojan.Gen.MBT
ESET-NOD32Python/Rozena.CY
CynetMalicious (score: 99)
APEXMalicious
KasperskyHEUR:Backdoor.Python.Agent.gen
AlibabaTrojan:Win32/Almi_Agent.f
ViRobotTrojan.Win.Z.Rozena.6391673
RisingTrojan.Generic@AI.97 (RDML:96tLCRHPDvBoNWRfY7SP+Q)
SophosMal/Generic-S
F-SecureTrojan.TR/Rozena.sfppf
EmsisoftTrojan.GenericKD.70068126 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Rozena.sfppf
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D42D279E
ZoneAlarmHEUR:Backdoor.Python.Agent.gen
GDataTrojan.GenericKD.70068126
AhnLab-V3Trojan/Win.Trojan-gen.R568372
ALYacTrojan.GenericKD.70068126
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CJH23
TencentWin32.Trojan.Rozena.Adhl
MaxSecureTrojan.Malware.119746888.susgen
FortinetW32/Rozena.CY!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Python/Rozena.CY?

Python/Rozena.CY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment