Malware

Troj/Rozena-AE (file analysis)

Malware Removal

The Troj/Rozena-AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Rozena-AE virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Troj/Rozena-AE?


File Info:

name: D5999A75DBD685FBEC92.mlw
path: /opt/CAPEv2/storage/binaries/e418e9b74dc9e17d1df0fabcc94896818c7f5c5f1a67b80f285e2211f3832324
crc32: 06893A49
md5: d5999a75dbd685fbec9200cdeb62a3c4
sha1: c26e5b959cfb7acc1aea34d6f4f66dd27a3926f8
sha256: e418e9b74dc9e17d1df0fabcc94896818c7f5c5f1a67b80f285e2211f3832324
sha512: c4717a0da2c34b8210889bdd8bca88274d2b30501a2298501743fb701a9f683568221fde7f88cde98a18362e4c37061e65858a718d4d41bf148975398142b2e8
ssdeep: 24:etGSfM+AW6wP8Lpi/qQ/Twt/h1cL3XIJKN7tkZf7OzYWI+ycuZhNeYakShNPNnq:66RNFi3/KcrNcJ7Ozz1uleYa3hXq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A371EF0793E8466BE0B74B306EF3472A37B4F8508B76976E0D80422DBCA16644E31BB5
sha3_384: 3eb113141156c4c83df7163b53c946c69b0c577d00083ef3d6e6a362ed6737da20b7671297b6323afd8cac31fd5ad866
ep_bytes: ff250020001000000000000000000000
timestamp: 2024-04-19 01:33:27

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: jdd3wq11.dll
LegalCopyright:
OriginalFilename: jdd3wq11.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Troj/Rozena-AE also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.93994
FireEyeTrojan.GenericKDZ.93994
SkyhighGenericRXVM-IM!D5999A75DBD6
ALYacTrojan.GenericKDZ.93994
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of PowerShell/Rozena.BI
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Convagent.gen
BitDefenderTrojan.GenericKDZ.93994
TencentTrojan.MSIL.Rozena.16000451
EmsisoftTrojan.GenericKDZ.93994 (B)
GoogleDetected
F-SecureTrojan.TR/Rozena.Gen
VIPRETrojan.GenericKDZ.93994
SophosTroj/Rozena-AE
GDataTrojan.GenericKDZ.93994
VaristW32/Rozena.HS.gen!Eldorado
AviraTR/Rozena.Gen
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D16F2A
ZoneAlarmHEUR:Trojan.MSIL.Convagent.gen
MicrosoftTrojan:MSIL/Rozena.HNS!MTB
McAfeeGenericRXVM-IM!D5999A75DBD6
PandaTrj/GdSda.A
IkarusTrojan.PowerShell.Rozena
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/GenericKDZ.68387!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Rozena.BL

How to remove Troj/Rozena-AE?

Troj/Rozena-AE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment