Malware

Win32/Rozena.BBA removal instruction

Malware Removal

The Win32/Rozena.BBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.BBA virus can do?

  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Win32/Rozena.BBA?


File Info:

crc32: 71709AE5
md5: f5ea028939956020ecd50270f105881e
name: F5EA028939956020ECD50270F105881E.mlw
sha1: 02a1d9186873ad5794ac9f7b7ef62a8ded5677ec
sha256: 3dd610edd4f40eec9a31ef11b9188210922b09273f2fcf26bf0bb268217af80b
sha512: c777b61833923d7e96d1a2b2543a48ddf139f521a2b263b3c0fbc2a51d314440b0c0c2c4737418abedb1323cb4ca47fcd6ea5900a3a91e813ea0798771800b6d
ssdeep: 6144:CkwaQKKJOlJvSd0zW1+daC208yk4CuMS3mxV1ZTa3iifi1Q:TwaHTrSaCMMJ0ra62rT2iQcQ
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Rozena.BBA also known as:

K7AntiVirusTrojan ( 005789561 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Meterpreter
ALYacTrojan.GenericKD.36429420
CylanceUnsafe
ZillyaTrojan.Rozena.Win32.114288
SangforTrojan.Win32.Meterpreter.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Shelma.6b4210c1
K7GWTrojan ( 005789561 )
Cybereasonmalicious.939956
CyrenW32/Trojan.FCRS-2757
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.BBA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Shelma.bfjg
BitDefenderTrojan.GenericKD.36429420
MicroWorld-eScanTrojan.GenericKD.36429420
Ad-AwareTrojan.GenericKD.36429420
SophosMal/Generic-S
F-SecureTrojan.TR/Rozena.eomgl
BitDefenderThetaGen:NN.ZexaF.34670.s8Y@aiwitnn
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.OUTBREAK.USMANC221
McAfee-GW-EditionGenericRXNU-FS!F5EA02893995
FireEyeGeneric.mg.f5ea028939956020
EmsisoftTrojan.GenericKD.36429420 (B)
WebrootW32.Malware.Gen
AviraTR/Rozena.eomgl
MicrosoftTrojan:Win32/Meterpreter.A
ArcabitTrojan.Generic.D22BDE6C
AegisLabTrojan.Win32.Shelma.4!c
ZoneAlarmTrojan.Win32.Shelma.bfjg
GDataTrojan.GenericKD.36429420
AhnLab-V3Malware/Win32.RL_Generic.R371099
McAfeeGenericRXNU-FS!F5EA02893995
MAXmalware (ai score=84)
VBA32BScope.Trojan.Shelma
MalwarebytesMalware.AI.3033102492
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.OUTBREAK.USMANC221
RisingTrojan.Rozena!8.6D (CLOUD)
YandexTrojan.Shelma!IFiZuij0jGU
IkarusTrojan.Win32.Rozena
FortinetW32/Rozena.BBA!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.Meterpreter.HgIASQIA

How to remove Win32/Rozena.BBA?

Win32/Rozena.BBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment