Trojan

Trojan:Win32/Rombertik.D removal guide

Malware Removal

The Trojan:Win32/Rombertik.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rombertik.D virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Rombertik.D?


File Info:

crc32: EB829EDD
md5: efc9040f587a5dd9e1de4707ec1ed8c5
name: yfoye_dump.exe
sha1: 43e7b85bb4282b731a8cbcd41a53fcaed49af0ab
sha256: c2581af6d4ff858b9fdf6c3bb6c32f988873057c0c28342b4c4bfa659ca5c0a8
sha512: d649675d1092dbc6ce7af3f83eaf048f1f4bbd6a15dfe8087ecedbbe1c837ff6de1264a0d5239cebc1451e8a6e624afee7e13a98b4b4a08c7f91218908e799fd
ssdeep: 384:kDdB16rbw9tkVR/2thvZkYqIgKkZtiycNPwvPyHWPbwHowHSWQEkE6S+j:kJB1ubWashRm8/PwvPKWPQB7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Rombertik.D also known as:

BkavW32.VariantKazyAS.Trojan
DrWebTrojan.Rombertik.1
MicroWorld-eScanGen:Variant.Kazy.122902
FireEyeGen:Variant.Kazy.122902
CAT-QuickHealTrojan.Generic.20818
Qihoo-360HEUR/QVM20.1.Malware.Gen
McAfeeGeneric Trojan.he
CylanceUnsafe
VIPRETrojan-Spy.Win32.Zbot.gen (v)
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusSpyware ( 0055e3db1 )
BitDefenderGen:Variant.Kazy.122902
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.f587a5
TrendMicroTROJ_GEN.R034E01GP15
BitDefenderThetaGen:NN.ZexaF.34096.cuW@aKKbakf
F-ProtW32/Injector.A.gen!Eldorado
SymantecInfostealer.Retga.A!gm
ESET-NOD32a variant of Win32/Spy.Agent.OLJ
APEXMalicious
AvastWin32:Rombertik-A [Trj]
GDataGen:Variant.Kazy.122902
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Rombertik.de704c0d
NANO-AntivirusTrojan.Win32.Rombertik.fetfqw
RisingSpyware.Agent!8.C6 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Kazy.122902 (B)
ComodoMalware@#24ocuy0rbogr3
ZillyaTrojan.Agent.Win32.531762
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.nt
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACO
IkarusTrojan-Spy.Carbon
CyrenW32/Injector.A.gen!Eldorado
JiangminTrojan/Generic.bdxyc
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Agent.lssyn
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Rombertik.D
ArcabitTrojan.Kazy.D1E016
SUPERAntiSpywareTrojan.Agent/Gen-Rombertik
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Rombertik.R126327
Acronissuspicious
VBA32Trojan.Rombertik
Ad-AwareGen:Variant.Kazy.122902
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R034E01GP15
TencentWin32.Trojan.Hijacker.Apmv
YandexTrojan.Agent!zZKhalg2EfQ
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.OLJ!tr
AVGWin32:Rombertik-A [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan:Win32/Rombertik.D?

Trojan:Win32/Rombertik.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment