Malware

Win32/Rozena.ACE (file analysis)

Malware Removal

The Win32/Rozena.ACE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.ACE virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Rozena.ACE?


File Info:

name: 0E22E10FA5ED3C00392B.mlw
path: /opt/CAPEv2/storage/binaries/776199ebd18d7533b6f82db4a85ef9b92b88d6676157a96e373943a2a53966a5
crc32: 4BC84090
md5: 0e22e10fa5ed3c00392b0476593e5873
sha1: 506c1f72096835ca03ea2dcd8d22a8810ed065aa
sha256: 776199ebd18d7533b6f82db4a85ef9b92b88d6676157a96e373943a2a53966a5
sha512: e770d1a286cadca2a706b707ed80750fbd237a13a8a8cc5af18ecfe0e292731582b736ff63657bf87bba72ceff39b02c9ee5a27e00134f125847eccdf9d0bd98
ssdeep: 768:8YKlOFobNdNoTQXbOfq1BkgRv4KrdmC+GgYWByWFQdZ:8LlBbNd+TYbOfgZ4cdmQ3OylH
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1CA13FA286AACC11EE6BF9FB93DD025D189B5A3632602D7971C88079FC853B44CE1177B
sha3_384: f712e030748e21a3563b224f75588b2afba04154c9d3d9d5fc5b8efa1f7420f209ad560e8aea640df66c53897f8599cf
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-12 02:26:09

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0
InternalName: sys.exe
LegalCopyright: 1.0
OriginalFilename: sys.exe
ProductVersion: 1.0
Assembly Version: 1.0.0.0

Win32/Rozena.ACE also known as:

LionicTrojan.Win32.Boxter.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanHeur.BZC.PZQ.Boxter.826.F2F9DB08
FireEyeHeur.BZC.PZQ.Boxter.826.F2F9DB08
McAfeeArtemis!0E22E10FA5ED
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005663a81 )
K7AntiVirusTrojan ( 005663a81 )
SymantecBackdoor.Cobalt
ESET-NOD32Win32/Rozena.ACE
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Cobalt.qp
BitDefenderHeur.BZC.PZQ.Boxter.826.F2F9DB08
AvastWin64:Trojan-gen
TencentWin32.Backdoor.Cobalt.Gbq
Ad-AwareHeur.BZC.PZQ.Boxter.826.F2F9DB08
EmsisoftHeur.BZC.PZQ.Boxter.826.F2F9DB08 (B)
TrendMicroTROJ_GEN.R002C0WLF21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Rozena
GDataHeur.BZC.PZQ.Boxter.826.F2F9DB08
WebrootW32.Trojan.Dropper
AviraTR/Rozena.xjufs
MAXmalware (ai score=85)
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.C4300851
ALYacHeur.BZC.PZQ.Boxter.826.F2F9DB08
MalwarebytesMalware.AI.44037454
TrendMicro-HouseCallTROJ_GEN.R002C0WLF21
FortinetW32/Rozena.ACE!tr
AVGWin64:Trojan-gen
Cybereasonmalicious.fa5ed3
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Rozena.ACE?

Win32/Rozena.ACE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment