Malware

Win32/Rozena.UF (file analysis)

Malware Removal

The Win32/Rozena.UF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.UF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

www.flash.cn

How to determine Win32/Rozena.UF?


File Info:

crc32: 5E7958E1
md5: 132817ef436c0d7a04558d45b6be9498
name: flashplayer_install_cn.exe
sha1: 11ed1ba3db102fc7aa75d4ff9928ea97f9226356
sha256: a5b2aadb51b846effd9a1e262aa1b0a76646cfb680e9ad3183763ec0ccc64279
sha512: 464d4f0999e749edecad60d985c387a0a0686e5fd426a11907f6d57a78daa2c13b9ccfcae28afd290b25266f0f405fc3f9ecca97065d86e0adc37a9d448bf7a3
ssdeep: 24576:FNcBtkfUdzxND1zJLnQEKbcQHmtrhy1xTbrQpE3W8OREWuG63wnxNlMeuikeOGV4:k1VND1lLnybEtrh0xTgpP6tr30NW3U4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Rozena.UF also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42684200
CAT-QuickHealTrojan.Shellexec
McAfeeArtemis!132817EF436C
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005050c51 )
BitDefenderTrojan.GenericKD.42684200
K7GWTrojan ( 005050c51 )
Cybereasonmalicious.f436c0
Invinceaheuristic
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42684200
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/2144FlashPlayer.ee0cd9b9
NANO-AntivirusTrojan.Win32.ShellCode.hcwqhg
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Duwe
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42684200 (B)
ComodoMalware@#61y5jxagtx3u
F-SecureHeuristic.HEUR/AGEN.1001580
DrWebExploit.ShellCode.26
ZillyaTrojan.Generic.Win32.995180
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.132817ef436c0d7a
SophosMal/Generic-S
IkarusTrojan.Win32.Occamy
CyrenW32/Trojan.LJHH-6817
AviraHEUR/AGEN.1001580
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Win32.Presenoker
ArcabitTrojan.Generic.D28B4F28
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2446793
Acronissuspicious
ALYacTrojan.GenericKD.42684200
Ad-AwareTrojan.GenericKD.42684200
PandaTrj/CI.A
ESET-NOD32Win32/Rozena.UF
TrendMicro-HouseCallTROJ_GEN.R002H07BQ20
RisingPUF.2144FlashPlayer!8.1141E (TFE:4:JBjj9y11BLS)
YandexTrojan.DR.Delf!kVI32hz/bG8
FortinetW32/Rozena.DY!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Rozena.UF?

Win32/Rozena.UF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment