Threat Database Trojans Trojan.Rozena.HA

Trojan.Rozena.HA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,887
Threat Level: 80 % (High)
Infected Computers: 536
First Seen: April 29, 2021
Last Seen: July 24, 2026
OS(es) Affected: Windows

The detection of Trojan.Rozena.HA on your system indicates a potential security threat that requires immediate attention. This type of threat is generally associated with malicious software designed to compromise the security and integrity of your computer. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Trojan.Rozena.HA?

Trojan.Rozena.HA is a type of malware that can infiltrate your system without your knowledge or consent. The term "Trojan" refers to a broad category of malware that disguises itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to your computer. Once inside, it can cause a range of problems, from stealing sensitive information to disrupting system performance.

How Trojan.Rozena.HA Operates

Malware like Trojan.Rozena.HA typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its creators, allowing them to control your computer remotely. This can lead to the installation of additional malware, theft of personal data, or even the use of your computer for malicious activities such as spreading spam or participating in botnets.

Symptoms of Infection

Identifying a Trojan.Rozena.HA infection can be challenging, as it often does not display obvious symptoms. However, you might notice that your computer is running slower than usual, or you may see unexpected pop-ups, changes in your browser settings, or unfamiliar programs installed on your system. In some cases, you might also experience frequent crashes or freezes, indicating that something is amiss.

How to Remove Trojan.Rozena.HA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the Trojan.Rozena.HA malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed without your consent. Be cautious, as some legitimate programs might be masquerading as malware.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any changes made by the malware, such as altered home pages or the installation of malicious extensions.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Rozena.HA from your system requires a combination of the right tools and a methodical approach. By following the steps outlined above and maintaining good computer hygiene, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when clicking on links or downloading software, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to protecting your digital assets and ensuring the integrity of your computer system.

Analysis Report

General information

Family Name: Trojan.Rozena.HA
Signature status: No Signature

Known Samples

MD5: 8fe473fbd7509f14d207d5805af37e57
SHA1: a2f5f4e1e82535d6f20a9431fd4525a19b2d0247
SHA256: 5AC184863208CEAFE6C78685C09A4DE97F00E1DBB2DF9A4A83D282DA259917BD
File Size: 678.63 KB, 678632 bytes
MD5: 1161eb15472f87895b4a8324eb19fb44
SHA1: bbdf1f1ff216e04945af495be57001f9810dc66f
SHA256: C66434C479D6B6A5531FAC95ABB70C26EBE730D7B5CABAF04AF2006CBAEF5E68
File Size: 1.18 MB, 1180904 bytes
MD5: 46d39c7423b5c48e1a3b38381af92c5b
SHA1: 144a39fd176499137cd06bd675d976a588e32a3c
SHA256: E1DED383E5FAD9D35D25395DAC924B0926AA96995F627DD2F2CA941B71473B6F
File Size: 1.10 MB, 1096192 bytes
MD5: 0b1470997d37ced6f63dac9d77c39eb4
SHA1: 427913afaf0443de10c8078b83e068f6507da51e
SHA256: 57355CE0D63C4B7ACE41916C7D393CD73A6D82A8E07C28840077034288626BDC
File Size: 1.66 MB, 1661440 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Simon Tatham
File Description
  • SSH, Telnet, Rlogin, and SUPDUP client
  • SSH, Telnet and Rlogin client
File Version
  • Release 0.76 (with embedded help)
  • Release 0.74 (with embedded help)
  • Release 0.73 (with embedded help)
Internal Name PuTTY
Legal Copyright
  • Copyright © 1997-2019 Simon Tatham.
  • Copyright © 1997-2020 Simon Tatham.
  • Copyright © 1997-2021 Simon Tatham.
Original Filename PuTTY
Product Name PuTTY suite
Product Version
  • Release 0.76
  • Release 0.74
  • Release 0.73

Digital Signatures

Signer Root Status
Simon Tatham COMODO RSA Certification Authority Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • imgui
  • packed
  • x86

Block Information

Total Blocks: 1,746
Potentially Malicious Blocks: 242
Whitelisted Blocks: 1,500
Unknown Blocks: 4

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x 0 x x 0 x x x x 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 x 0 x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 x 0 x 0 x x 0 x 0 x x 0 x x x x x 0 x x x x x x 0 x x 0 0 x x 0 0 x 0 x x x x x 0 x x x x x x x 0 x 0 0 0 0 0 x 0 x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x 0 0 x x x x x x x x x x x x x 0 x x 0 0 0 0 0 x x x x x x x x x x x 0 x x 0 0 0 x x x x x x x x x 0 x x 0 x x x 0 x x x 0 x x x x x x x x x x x 0 x x x x x 0 x x 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 x 0 x 0 x x 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rozena.HA

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserNameEx
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState