Trojan

Trojan:MSIL/Rozena.PSTV!MTB information

Malware Removal

The Trojan:MSIL/Rozena.PSTV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Rozena.PSTV!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Rozena.PSTV!MTB?


File Info:

name: 642455FE9C9B92E7242F.mlw
path: /opt/CAPEv2/storage/binaries/699f1595bdd543db5c7141d24e26505ee4473816278e8f708957c270514734cf
crc32: BC69ED54
md5: 642455fe9c9b92e7242f2b98b5becf9b
sha1: 3ab298ecfbb5c6d386f53f6e73a0f5ab33117973
sha256: 699f1595bdd543db5c7141d24e26505ee4473816278e8f708957c270514734cf
sha512: 598484b7c5636b7b177a5094cb2aa5a7383f45e5840a659580bbbb20a21c5e2854c1001bd561596a27a4ab5237c55b69e45072b36775c27da5a4d1e5e11a01c2
ssdeep: 96:6bwrFZOG9wEQPFFFxrcnsTmCu/QJxyupz1BTg711sdPzNt:6MxwElnsTmCWEx3B7dZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149129622D380A375D1F68277FAABD3721A7AAE1454A7033F20C8FE17B965E115833614
sha3_384: f366795e7ea60ef68a32ae5e78edaf1a8d4b957a4faf0f14a6384e7d676b6606b4f0c51f6fd2a26c4eaa3ad3053f5729
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-11-17 05:39:37

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: deceptively.exe
LegalCopyright:
OriginalFilename: deceptively.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Rozena.PSTV!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicRiskware.Win32.DotDo.1!c
MicroWorld-eScanGen:Variant.MSIL.Agent.12
FireEyeGeneric.mg.642455fe9c9b92e7
SkyhighBehavesLike.Win32.PWSZbot.zt
ALYacGen:Variant.MSIL.Agent.12
Cylanceunsafe
ZillyaAdware.Generic.Win32.142869
SangforSuspicious.Win32.Save.a
K7AntiVirusAdware ( 0055c5971 )
AlibabaAdWare:MSIL/Dotdo.40ee3b8e
K7GWAdware ( 0055c5971 )
ArcabitTrojan.MSIL.Agent.12
BitDefenderThetaGen:NN.ZemsilCO.36744.am0@aSJeQnk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Adware.Dotdo.IA
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:VHO:AdWare.MSIL.Convagent.gen
BitDefenderGen:Variant.MSIL.Agent.12
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Risk.ADWARE.Vgil
EmsisoftGen:Variant.MSIL.Agent.12 (B)
F-SecureHeuristic.HEUR/AGEN.1308482
VIPREGen:Variant.MSIL.Agent.12
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.MSIL.Dotdo
WebrootW32.Malware.Gen
VaristW32/DotDo.AB.gen!Eldorado
AviraHEUR/AGEN.1308482
Antiy-AVLGrayWare/Win32.Dotdo
Kingsoftmalware.kb.c.997
XcitiumApplication.MSIL.Dotdo.DF@8m9j7r
MicrosoftTrojan:MSIL/Rozena.PSTV!MTB
ZoneAlarmnot-a-virus:VHO:AdWare.MSIL.Convagent.gen
GDataGen:Variant.MSIL.Agent.12
GoogleDetected
AhnLab-V3Adware/Win32.Dotdo.R283035
McAfeeArtemis!642455FE9C9B
MAXmalware (ai score=89)
MalwarebytesAdware.DotDo.Generic.TskLnk
YandexPUA.Dotdo!dUnJ8sRzzbk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.2494!tr
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Trojan:MSIL/Rozena.PSTV!MTB?

Trojan:MSIL/Rozena.PSTV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment