Trojan

Rozena.Trojan.Shell.DDS information

Malware Removal

The Rozena.Trojan.Shell.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rozena.Trojan.Shell.DDS virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Rozena.Trojan.Shell.DDS?


File Info:

name: FA7C91FA17F1FE09271D.mlw
path: /opt/CAPEv2/storage/binaries/246b554bbade722daf857642e66d6c7a7c0c24559c756e67be16b2d2fd47d5c5
crc32: 037F5563
md5: fa7c91fa17f1fe09271d70db89e2eaa5
sha1: 1096864c0f357b2b8b1e65d5c4043718be3b9e42
sha256: 246b554bbade722daf857642e66d6c7a7c0c24559c756e67be16b2d2fd47d5c5
sha512: 970db2ed0bbefca4084253cebde702907d2f2c7d6b384267b34cae63c17bf68c942500ab92ec7e3926a726e886636538e88ac91322931142090a4da94448c18c
ssdeep: 768:ITkbBirSVr/XF37aOpo5fVo0QFmPp4ymmFLwcUhM+qD3g76IvlVhhLhp+Jz/oXq3:ITkBir8z1rtpo5fRQQh4uFbwqc76wTLG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14023F16479E8C8B6F1B7B931273D6747C21C38A3EE3C874C39822049A4717175E2AB67
sha3_384: 7c10c6b1d665eacc99b067709c1a026727eb8316404dd24e06180bb18fbcc51dcce3b6954fd0c9788ad38209f8e2707f
ep_bytes: 60be00d040008dbe0040ffff5783cdff
timestamp: 2009-07-15 10:30:27

Version Info:

Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.2.14
InternalName: ab.exe
LegalCopyright: Copyright 2009 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
Translation: 0x0409 0x04b0

Rozena.Trojan.Shell.DDS also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Razy.600488
ClamAVWin.Trojan.MSShellcode-6360728-0
CAT-QuickHealTrojan.Swrort.A
ALYacGen:Variant.Razy.600488
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 001172b51 )
K7AntiVirusTrojan ( 001172b51 )
CyrenW32/Swrort.D
SymantecPacked.Generic.347
ESET-NOD32a variant of Win32/Rozena.BJG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.600488
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Razy.600488
EmsisoftGen:Variant.Razy.600488 (B)
ComodoTrojWare.Win32.Rozena.A@4jwdqr
VIPREGen:Variant.Razy.600488
TrendMicroBackdoor.Win32.SWRORT.SMAL01
McAfee-GW-EditionSwrort.d
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fa7c91fa17f1fe09
IkarusTrojan.Win32.Swrort
AviraTR/Crypt.ULPM.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.D929A8
GDataGen:Variant.Razy.600488
GoogleDetected
AhnLab-V3Backdoor/Win32.Bifrose.R12476
McAfeeGenericRXAA-AA!FA7C91FA17F1
MAXmalware (ai score=86)
VBA32Trojan.Swrort
MalwarebytesRozena.Trojan.Shell.DDS
TrendMicro-HouseCallBackdoor.Win32.SWRORT.SMAL01
RisingTrojan.Crypto!8.364 (TFE:5:qRUE1u5wYD)
YandexTrojan.GenAsa!O0/tdGI4TGA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rozena.ABV!tr
BitDefenderThetaGen:NN.ZexaF.34796.cmKfamYdALfi
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a17f1f
PandaTrj/Genetic.gen

How to remove Rozena.Trojan.Shell.DDS?

Rozena.Trojan.Shell.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment