Malware

What is “Win32/Rozena.WZ”?

Malware Removal

The Win32/Rozena.WZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rozena.WZ virus can do?

  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Win32/Rozena.WZ?


File Info:

crc32: 62BFD210
md5: 620735ade127124e7419387194d4db96
name: x32.exe
sha1: ae8741ec454b6b81a66d800bce05c12fe1d4b1c6
sha256: 1e63f867bab9cbc7cd652c846334f87fe8ac05f4959086cf375fc4b3341d9117
sha512: f4a5db83d682760fc243133e689e15c7a6c2c7d2486a70ab4fea5378c8709684e73ceae97198a386778438e3b6d4c7f34aaf406a1cb2896dbadbfbb5bde4fdc5
ssdeep: 192:3HSykZahxHn9QgyBtX4SR4wefaN7f5oRK/SjN7AGY:XSykyDyLXrRwaN7fbyAp
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Rozena.WZ also known as:

MicroWorld-eScanTrojan.Agent.DDSN
FireEyeGeneric.mg.620735ade127124e
McAfeeBackDoor-FDRT!620735ADE127
CylanceUnsafe
K7AntiVirusTrojan ( 004cd8391 )
BitDefenderTrojan.Agent.DDSN
K7GWTrojan ( 004cd8391 )
Cybereasonmalicious.de1271
CyrenW32/Rozena.K.gen!Eldorado
SymantecBackdoor.Rozena
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan.Mexec.B
KasperskyTrojan.Win32.Cobalt.a
NANO-AntivirusTrojan.Win32.TrjGen.eegfaz
ViRobotTrojan.Win32.Agent.14336.DF
RisingTrojan.Swrort!1.BAB0 (CLASSIC)
Ad-AwareTrojan.Agent.DDSN
SophosTroj/Swrort-CG
ComodoTrojWare.Win32.Kryptik.BYGK@59ple7
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Swrort.41
ZillyaTrojan.Rozena.Win32.46773
Invinceaheuristic
McAfee-GW-EditionBackDoor-FDRT!620735ADE127
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Agent.DDSN (B)
IkarusTrojan.Win32.Swrort
F-ProtW32/Rozena.K.gen!Eldorado
JiangminTrojan.Generic.yke
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=80)
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.DDSN
ZoneAlarmTrojan.Win32.Cobalt.a
MicrosoftTrojan:Win32/Swrort.A
AhnLab-V3Trojan/Win32.Swrort.R270227
Acronissuspicious
VBA32Trojan.Cobalt
ALYacTrojan.Agent.DDSN
TACHYONTrojan/W32.Agent.14336.UN
ZonerTrojan.Win32.69381
ESET-NOD32a variant of Win32/Rozena.WZ
FortinetW32/Rozena.WZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360HEUR/QVM20.1.DF7F.Malware.Gen

How to remove Win32/Rozena.WZ?

Win32/Rozena.WZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment