Home Malware Programs Trojans Reoxtan

Reoxtan

Posted: March 28, 2006

Reoxtan is a dangerous trojan that steals user sensitive information such as many login names and passwords, networking settings, computer and PC information. It also records addresses of visited web sites, tracks user Internet activity and records keystrokes. Reoxtan transfers gathered data to a predetermined remote host. It may download additional instructions or files. The spyware disables Windows Firewall and alters computer security settings. It may act as a hidden proxy service. Reoxtan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 explorer.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun\%System%serviceexplorer.exe=1HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurityCenterAntiVirusDisableNotify=1HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileDisableNotifications=1HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileDoNotAllowExceptions=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0
Loading...