Trojan

Trojan:Win32/Rozena.E!bit removal tips

Malware Removal

The Trojan:Win32/Rozena.E!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rozena.E!bit virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Anomalous binary characteristics

How to determine Trojan:Win32/Rozena.E!bit?


File Info:

crc32: A1C74EFD
md5: ac41ac06ff699e02e02eb2224d5a3287
name: rubyremote.exe
sha1: 660da89b5b00c31a3f703871f7de4c46a506e5e5
sha256: a312b528dd430b85b3fd094774e366790e7718fcd58f3c76c850fe073483ed18
sha512: 61422458937f6a53e0eef4f056422351a6e8d9830ea4b0c7fd0ed401d9baa4379225518e512edcf60095edd9b769577e3d196ea70e36882d06b5c4316c1d0c04
ssdeep: 12288:PLJPXXMK2SRMxz2dwDq319o6sRt5PC4fwvJfrhzFdxLw:NgSGxmwDql+pBYBfrhz2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Rozena.E!bit also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Heur.Veil.5
FireEyeGeneric.mg.ac41ac06ff699e02
Qihoo-360HEUR/QVM01.1.AACB.Malware.Gen
McAfeeRDN/Generic Downloader.x
MalwarebytesTrojan.Downloader
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004b58b51 )
BitDefenderGen:Heur.Veil.5
K7GWTrojan ( 004b58b51 )
Cybereasonmalicious.6ff699
Invinceaheuristic
CyrenW32/Dipledel!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Heur.Veil.5
KasperskyTrojan-Downloader.Ruby.Liev.a
AlibabaTrojanDownloader:Win32/Rozena.21d69849
AegisLabTrojan.Ruby.Liev.a!c
TencentMalware.Win32.Gencirc.10b3637d
SophosMal/Veil-A
F-SecureHeuristic.HEUR/AGEN.1123614
ZillyaTrojan.Diple.Win32.77666
TrendMicroTROJ_GEN.R002C0DGF20
EmsisoftGen:Heur.Veil.5 (B)
IkarusTrojan.Win32.Diple
F-ProtW32/Dipledel!Eldorado
JiangminTrojan/Diple.dosz
AviraHEUR/AGEN.1123614
Antiy-AVLTrojan[RemoteAdmin]/Win32.WinVNC-based
Endgamemalicious (high confidence)
ArcabitTrojan.Veil.5
ZoneAlarmTrojan-Downloader.Ruby.Liev.a
MicrosoftTrojan:Win32/Rozena.E!bit
CynetMalicious (score: 90)
VBA32Backdoor.Ruby.FBook
MAXmalware (ai score=82)
CylanceUnsafe
ESET-NOD32Ruby/Rozena.D
TrendMicro-HouseCallTROJ_GEN.R002C0DGF20
RisingDownloader.Liev!8.382 (CLOUD)
YandexTrojan.Agent!HA73UzC/nOM
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Ruby_Liev.A!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Rozena.E!bit?

Trojan:Win32/Rozena.E!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment