Malware

Win32:Rosec removal guide

Malware Removal

The Win32:Rosec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Rosec virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Win32:Rosec?


File Info:

name: F565C402E3E2831C33C7.mlw
path: /opt/CAPEv2/storage/binaries/90b48a2146094d9c6e7bb39f57f9f094faec6feb6401abdcc0df2b8a3247740e
crc32: 155FBA44
md5: f565c402e3e2831c33c709d486a29665
sha1: 0e59bcbbbd53deaf8d614d36f9c78ab2c180ca83
sha256: 90b48a2146094d9c6e7bb39f57f9f094faec6feb6401abdcc0df2b8a3247740e
sha512: 7a9e896393fbf7adff68f6a249f24eeeac3bc51df871d69f3cf1cdf789bd690f53f9709c63fd0e5a7a7bae1be1d7b98bc1f8d380698fe48793e9fa57d195f538
ssdeep: 768:0fH0D1ImL140dSgLGvVLFR6VO4KDjUVy51RBhBDam+wUN/h:0P0DuO40dlGvWr6ccR3BDaFwY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171F37D2ABAC485FFD04189716F7396B8E2B1BC369A841B02F3D07F4F3E756C06116A56
sha3_384: 8718033a7f1f371cfc7cd92b70d06158a38a3ce7cf25c9579e5736c502ae803495c91b373a43cd3a6b1d7e964987b954
ep_bytes: b96c634000b800800000e808290000e8
timestamp: 2003-01-15 17:50:08

Version Info:

0: [No Data]

Win32:Rosec also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.HLLP.Sality.E
CAT-QuickHealW32.Sality.E3
McAfeeW32/Sality.i.gen
CylanceUnsafe
VIPREWin32.HLLP.Sality.E
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWVirus ( 0040f8141 )
K7AntiVirusVirus ( 0040f8141 )
CyrenW32/Trojan.III.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Sality.e
BitDefenderWin32.HLLP.Sality.E
NANO-AntivirusTrojan.Win32.Sality.bottkc
AvastWin32:Rosec
RisingWin32.Sality.e (CLASSIC)
Ad-AwareWin32.HLLP.Sality.E
SophosML/PE-A + W32/Sality-F
ComodoVirus.Win32.Sality.f0@1n9lrg
DrWebWin32.HLLP.Sector.17368
McAfee-GW-EditionW32/Sality.i.gen
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f565c402e3e2831c
EmsisoftWin32.HLLP.Sality.E (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.HLLP.Sality.E
JiangminWin32/Sality.d
AviraW32/Sality.f
MAXmalware (ai score=86)
ArcabitWin32.HLLP.Sality.E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
Acronissuspicious
ALYacWin32.HLLP.Sality.E
VBA32Win32.HLLP.Kuku.e
MalwarebytesMalware.Heuristic.1003
TencentVirus.Win32.Sality.tt
IkarusTrojan.Patched
FortinetW32/Sality.I!tr
BitDefenderThetaGen:NN.ZexaF.34698.kmW@aeoq0Wn
AVGWin32:Rosec
Cybereasonmalicious.2e3e28
PandaTrj/Genetic.gen

How to remove Win32:Rosec?

Win32:Rosec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment