Threat Database Trojans Trojan.Rozena.VE

Trojan.Rozena.VE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,613
Threat Level: 80 % (High)
Infected Computers: 147
First Seen: July 21, 2025
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Rozena.VE on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and step-by-step guidance on how to remove it from your system.

What Is Trojan.Rozena.VE?

Trojan.Rozena.VE is a type of malware that can compromise the security and integrity of your computer system. The term "Trojan" refers to a class of malware that disguises itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to a system. Once inside, it can perform a variety of malicious activities, depending on its design and the intentions of its creators.

How Trojan.Rozena.VE Operates

Malware like Trojan.Rozena.VE typically operates by exploiting vulnerabilities in software or manipulating users into installing it. Once installed, it can communicate with its command and control servers to receive instructions, which might include stealing sensitive information, installing additional malware, or using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

The specific operations of Trojan.Rozena.VE can vary, but common behaviors include data theft, unauthorized changes to system settings, and the installation of other malicious software. Its ability to evade detection and operate stealthily makes it a significant threat to computer security.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, several symptoms may indicate the presence of Trojan.Rozena.VE or similar malware on your system. These include, but are not limited to, unexpected changes to your system settings, unfamiliar programs or icons, significant slowdowns in system performance, frequent crashes or freezes, and pop-ups or other unwanted advertisements appearing on your computer or web browser.

Additionally, you might notice that your browser's homepage has changed without your consent, or you're being redirected to unwanted websites. These signs suggest that your system has been compromised, and you should take immediate action to secure it.

How to Remove Trojan.Rozena.VE

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode. This will limit the malware's ability to interfere with the removal process. Ensure you have an internet connection to download any necessary tools.
  2. Conduct a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the Trojan.Rozena.VE malware.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you do not recognize or that were installed without your knowledge. Be cautious and only remove programs you are sure are malicious or unnecessary.
  4. Reset Your Browser: Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot and Re-scan: After completing the above steps, restart your computer and perform another full scan with your anti-malware tool to ensure all threats have been removed.

Conclusion

Removing Trojan.Rozena.VE from your system requires careful and systematic steps to ensure all components of the malware are eliminated. By following the guidance provided, you can help protect your system and personal data from the risks associated with this and similar threats. Remember, prevention is key; keeping your software up to date, using strong antivirus software, and being cautious when downloading or installing new programs can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.Rozena.VE
Signature status: No Signature

Known Samples

MD5: 09185c1ad4f712cd749f8d8667a90f27
SHA1: 335b760ed6af210ef44b69dc908295c972ab5e70
SHA256: 1BF6115714CFBC15F5C5941E6331A9E90DF9480533D1E9B93FEA078C4404BB38
File Size: 660.48 KB, 660480 bytes
MD5: 65f9eb89320754449bbc2e9c88ac7fad
SHA1: 1d7f5a7752a058d681ba24d9b3931d3441d0e727
SHA256: 72B0A8530762B5D9B35502ACE961ED4223D39FA249FAEE86870F3B5965EBCB5E
File Size: 586.75 KB, 586752 bytes
MD5: dc1acf0a79d17a9d58d8194b201e0d6c
SHA1: 9f4fa69f2b04b46aedbfae93a386eda7047e0ac3
SHA256: 657AE404DE972E3E048355A485D7ABD6C27E1C8EC38642F9E8E0FCC855E8D7C9
File Size: 656.90 KB, 656896 bytes
MD5: 26ababb2dc8a689c3a91ecb4d80b4540
SHA1: 5d71fc8109496c22f5e0b0854081c1eb91e02c75
SHA256: C239B0DE0E70BA4902F48565C7AFD3B78DA685241B3E88073EB7362279704FC0
File Size: 665.32 KB, 665320 bytes
MD5: 474f69861de695e3517271b0e2648eca
SHA1: a8c726e95bf669754d8fa1142412a6c7d0c31499
SHA256: B45B226FE619BD8905D90FA112C29B43300D4CCB24E81D57529EB04917E5A2F7
File Size: 1.57 MB, 1570304 bytes
Show More
MD5: d61f7a48ff0cc2a5de0241beb1185b4b
SHA1: 3819ff88acec6189d9f8fe800feb4e59b3b02409
SHA256: CA96EDB88AC9FA0AF7C96565521323CD4D45E40CB63341875EB03DBFB027AF48
File Size: 590.85 KB, 590848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Manager
  • Synaptics
File Description
  • Manager
  • Synaptics Pointing Device Driver
File Version
  • 1.0.0.4
  • 1.0.0.0
Internal Name Manager
Legal Copyright © 2025 Manager
Product Name
  • Manager
  • Synaptics Pointing Device Driver
Product Version
  • 1.0.0.0

Digital Signatures

Signer Root Status
MyAppTest MyAppTest Self Signed

File Traits

  • dll
  • GetConsoleWindow
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,968
Potentially Malicious Blocks: 169
Whitelisted Blocks: 1,794
Unknown Blocks: 5

Visual Map

x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 0 0 0 x x 0 x x x x 0 0 0 x x x 0 0 x x 0 x 0 x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 0 0 0 0 0 x x x x x x 0 x 0 x x x 0 x x 0 x 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 ? x 0 0 0 0 x 0 0 x x 0 0 x 0 0 0 0 x x x 0 0 0 x 0 x 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 ? 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x x x x x x 0 x x x 0 0 0 0 0 0 0 x 0 x 0 x x x 0 x x x x x x 0 0 x ? ? x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x x 0 x x x x 0 0 0 x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 1 1 1 1 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 1 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rozena.VE

Files Modified

File Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxab1f.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\downloads\._cache_a8c726e95bf669754d8fa1142412a6c7d0c31499_0001570304 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_a8c726e95bf669754d8fa1142412a6c7d0c31499_0001570304 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 'k�8��8tX��B �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (k�8��8tX��B �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 )k�8��8tX��B �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 *k�8��8tX��B �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Anti Debug
  • NtQuerySystemInformation
Network Winhttp
  • WinHttpOpen
Service Control
  • OpenSCManager
Process Shell Execute
  • ShellExecuteEx
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

runas c:\users\user\downloads\._cache_a8c726e95bf669754d8fa1142412a6c7d0c31499_0001570304
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate

Trending

Most Viewed

Loading...