Trojan

About “Trojan:MSIL/Rompriv.A” infection

Malware Removal

The Trojan:MSIL/Rompriv.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Rompriv.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan:MSIL/Rompriv.A?


File Info:

crc32: 083A84B1
md5: b9aea4d4609e250de1256b0f0e29bf23
name: B9AEA4D4609E250DE1256B0F0E29BF23.mlw
sha1: 990cd6db0fc3cbe7a1da449baa87c2f72cbde466
sha256: a09f334574f49f9cb0f53b7ee8e8c42b9a222bb87aaaf97db01b0c6e3b59341a
sha512: 3489e59da8f60d48b206fe5dc1d9ed87a11523affe8eba46bd5fa4e4633236267792e256c20efbfe4331817ee95772bce9f337975dd84410beb780405aebabde
ssdeep: 6144:6hLzMABCUA030XTVbeDYsyfrCYuATVANM7:24AQ03QbP7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: New Folder.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription: x3a6x3acx3bax3b5x3bbx3bfx3c2 x3b1x3c1x3c7x3b5x3afx3c9x3bd
OriginalFilename: New Folder.exe

Trojan:MSIL/Rompriv.A also known as:

K7AntiVirusTrojan ( 004c0fcd1 )
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.39301
CynetMalicious (score: 99)
ALYacBackdoor.MSIL.Agent.DB
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.285950
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004c0fcd1 )
Cybereasonmalicious.4609e2
CyrenW32/Trojan.YCMU-2948
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/CoinMiner.DO
ZonerTrojan.Win32.17413
APEXMalicious
AvastMSIL:BitCoinMiner-F [Trj]
ClamAVWin.Trojan.Virut-369
KasperskyHEUR:Trojan-Dropper.MSIL.Dapato.gen
BitDefenderBackdoor.MSIL.Agent.DB
NANO-AntivirusVirus.Win32.Virut.pnbk
MicroWorld-eScanBackdoor.MSIL.Agent.DB
Ad-AwareBackdoor.MSIL.Agent.DB
SophosML/PE-A
ComodoMalware@#k3trcwkm5t4b
BitDefenderThetaGen:NN.ZemsilF.34236.Am3@aeGXaVl
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_COINMINE.WE
McAfee-GW-EditionBehavesLike.Win32.Generic.gt
FireEyeGeneric.mg.b9aea4d4609e250d
EmsisoftBackdoor.MSIL.Agent.DB (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.FrauDrop.pau
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.20C8B3
KingsoftWin32.Troj.FrauDrop.(kcloud)
MicrosoftTrojan:MSIL/Rompriv.A
ArcabitBackdoor.MSIL.Agent.DB
GDataBackdoor.MSIL.Agent.DB
AhnLab-V3Trojan/Win32.FrauDrop.C205522
McAfeeArtemis!B9AEA4D4609E
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
PandaGeneric Malware
TrendMicro-HouseCallTROJ_COINMINE.WE
YandexTrojan.DR.FrauDrop!xut32OBUNis
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DB!tr
AVGMSIL:BitCoinMiner-F [Trj]

How to remove Trojan:MSIL/Rompriv.A?

Trojan:MSIL/Rompriv.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment