Malware

How to remove “Win32/Rozena.AFR”?

Malware Removal

The Win32/Rozena.AFR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.AFR virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Rozena.AFR?


File Info:

name: 7AD4A977C33C9F9E01C5.mlw
path: /opt/CAPEv2/storage/binaries/711f6221db6147eff23fac6d261211d409efc5cb96bdb84451985543353c793b
crc32: 85370C27
md5: 7ad4a977c33c9f9e01c536ffcae161ef
sha1: 8538e6c01fbb2e9dbd385895bb315b61604f15ec
sha256: 711f6221db6147eff23fac6d261211d409efc5cb96bdb84451985543353c793b
sha512: f2e044ee5eb7ae3c93dfe23007961e46ee5ca42e96cd81e98df065dbf2d773d261f168345e57c01eaa7aa55ae714b68304fa736e742e31cd38c82e433040add6
ssdeep: 1536:YmzZFLyWG4m2oLAcrIN1yNrBHmwyDu3q2hNbi8D2ZjwrN8:YmzZFLbtXU0QrBHp2SK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B3A3F7A7BFC2ED93E5110339C9F98319123EF6D01B86871B2D2698390B576A07FC5646
sha3_384: 3f0895ea14f761bb395cc3c5b4e303fc30ec37e6cb58d31ad9ec110897993efc82067c6ed7f0f7cbfb01ce2383c183ce
ep_bytes: 83ec0cc7059853400000000000e88e03
timestamp: 2016-07-30 14:25:09

Version Info:

0: [No Data]

Win32/Rozena.AFR also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.7ad4a977c33c9f9e
MalwarebytesGeneric.Malware.AI.DDS
CrowdStrikewin/malicious_confidence_60% (D)
ESET-NOD32a variant of Win32/Rozena.AFR
APEXMalicious
ClamAVWin.Malware.Fugrafa-9865662-0
KasperskyHEUR:Trojan.Win32.Generic
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SophosGeneric ML PUA (PUA)
ZoneAlarmHEUR:Trojan.Win32.Generic
GoogleDetected
IkarusTrojan.Win32.Powerless
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Rozena.AFR?

Win32/Rozena.AFR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment