Malware

Win32/Rozena.BEF removal tips

Malware Removal

The Win32/Rozena.BEF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.BEF virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Rozena.BEF?


File Info:

crc32: ED9A0378
md5: 62d1e7bfb8d79e83afa99ba705d88c3d
name: 62D1E7BFB8D79E83AFA99BA705D88C3D.mlw
sha1: be55f3a93cdb7367210d1de12c959078397dad8a
sha256: 263c902f99ea52a5d89a9b018b0484b3384e4208588048cb7b0da33f2efd063b
sha512: e832f27316329ac8b88f9db0258f9513db20e9912b80d3768b561e3ba6e9954c11cf4bb9cccacf8e75d64e5aeb75216a380009323d3c195180c4a34552f6c3dc
ssdeep: 192:fZnq6bQEwdjZoOHqeLKvLb6XPa3LZYVotVe280QU6:fM6091oOKKXi7wiVeaQU6
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: pnPxUYhcM
InternalName: TochKrvUN
FileVersion: 4305289.7127591
CompanyName: YfFNMzIATHBu
ProductName: kqyOiqmV
ProductVersion: 8870659.4808216
FileDescription: KivORetf
OriginalFilename: SFDxwEagdi
Translation: 0x0809 0x04e4

Win32/Rozena.BEF also known as:

K7AntiVirusTrojan ( 0057e31b1 )
CynetMalicious (score: 100)
ALYacGen:Heur.ManBat.1
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
AlibabaTrojan:Win32/Rozena.e4860f9a
K7GWTrojan ( 0057e31b1 )
Cybereasonmalicious.fb8d79
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.BEF
AvastWin32:TrojanX-gen [Trj]
BitDefenderGen:Heur.ManBat.1
MicroWorld-eScanGen:Heur.ManBat.1
Ad-AwareGen:Heur.ManBat.1
SophosGeneric PUA LO (PUA)
BitDefenderThetaGen:NN.ZexaF.34770.aK0@a4zxmdni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.62d1e7bfb8d79e83
EmsisoftGen:Heur.ManBat.1 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.8M831N
McAfeeArtemis!62D1E7BFB8D7
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_GEN.R002H09FU21
IkarusTrojan.Win32.Meterpreter
FortinetW32/Rozena.BEF!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASXgA

How to remove Win32/Rozena.BEF?

Win32/Rozena.BEF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment