AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 04:10:18 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4765 Members
Latest Member: hunteryazmin
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: Trojan.Rohoteng 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Trojan.Rohoteng  (Read 576 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
Trojan.Rohoteng
« on: September 19, 2005, 11:44:11 PM »

Trojan.Rohoteng is a Trojan horse that attempts to steal confidential information related to online games running on the compromised computer. It then attempts to send this information to predetermined Web sites.

When Trojan.Rohoteng is executed, it performs the following actions:

   1. Creates the following mutex, so that only one copy of the Trojan runs on the compromised computer at one time:

      ONLY_MUTEX_sg2008_ro_hot_Gen

   2. Adds the value:

      "reseurce" = "[PATH TO TROJAN FILE]"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that it runs every time Windows starts.

   3. Checks the titles of all open windows on the compromised computer, to check if the titles match one of the following strings:

          * Ragnarok
          * ODINGAME_ONLINE

            Note: If the title of an open window matches one of these strings, the Trojan attempts to steal information about the process associated with that window.

   4. Attempts to send this information to the following Web sites:

          * [http://]www.lineage0.com/[REMOVED]/3guo.asp
          * [http://]www.lineage0.com/[REMOVED]/ro.asp
          * [http://]www.lineage0.com/[REMOVED]/hot.asp


REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/trojan.rohoteng.html


To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit
   3. Click OK.
   4. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

   5. In the right pane, delete the value:

      "reseurce" = "[PATH TO TROJAN FILE]"

   6. Exit the Registry Editor.
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: Trojan.Rohoteng « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!