Trojan

Trojan:Win32/Rovnix.SA removal guide

Malware Removal

The Trojan:Win32/Rovnix.SA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rovnix.SA virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Loads a driver
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

Related domains:

tj.fame3.com

How to determine Trojan:Win32/Rovnix.SA?


File Info:

crc32: 4BEFA4F5
md5: e96efc188d181678379d4fa9431383f9
name: gpt______win7____________v0.9.exe
sha1: 27fde7dd85894234d78c77b908eb51f16fc583ca
sha256: 7c49f840604fa3092688869d0d4ee454ecf6a5bae4570fb847702be6e95d6432
sha512: c7e4f687b5a00d72af7e11c7cb33a9896cd9f080dfd5a38ab3b4b8c73e861c33bf8dac3c0d8b293bbed12af7320b387a6541a65f1acce16373af149e6a52ef96
ssdeep: 98304:bUf7Ul2ejSncfWK5I45F4aZQ0QsTssFCd6mDWt2QfjA8Xk+SyCyDBUOj:gf7Ul21nGWiIn0zQ0Cdr6t2QfjrvxCy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2014
FileVersion: 1.0
ProductVersion: 3.3.8.0
Translation: 0x0804 0x04b0

Trojan:Win32/Rovnix.SA also known as:

DrWebTrojan.MulDrop8.63395
MicroWorld-eScanGen:Variant.Strictor.230569
FireEyeGeneric.mg.e96efc188d181678
CAT-QuickHealTrojan.Generic
McAfeeArtemis!E96EFC188D18
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0053f6541 )
BitDefenderGen:Variant.Strictor.230569
Cybereasonmalicious.88d181
TrendMicroTROJ_GEN.R002C0DLD19
BitDefenderThetaAI:Packer.DA30C2BF20
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-6867844-0
GDataGen:Variant.Strictor.230569
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/KMSAuto.116e3692
NANO-AntivirusTrojan.Win32.Rovnix.fmmouy
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Rovnix.Akyw
Endgamemalicious (moderate confidence)
ComodoMalware@#1w494yboe19mb
F-SecureHeuristic.HEUR/AGEN.1007691
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Strictor.230569 (B)
IkarusHackTool.Win32.Wpakill
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Agent.qwmsp
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Rovnix.SA
ArcabitTrojan.Strictor.D384A9
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Rovnix.C2911684
VBA32Trojan.MulDrop
ALYacGen:Variant.Strictor.230569
Ad-AwareGen:Variant.Strictor.230569
ESET-NOD32a variant of Win32/Packed.Autoit.AC suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0DLD19
RisingRootkit.Agent!1.BF1F (CLASSIC)
YandexTrojan.AvsArher.bS7elO
FortinetW32/Rovnix.AT!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM11.1.DC21.Malware.Gen

How to remove Trojan:Win32/Rovnix.SA?

Trojan:Win32/Rovnix.SA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment