Threat Database Trojans Trojan.Rugmi.BB

Trojan.Rugmi.BB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,517
Threat Level: 80 % (High)
Infected Computers: 2,642
First Seen: October 2, 2024
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.BB on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating mechanisms, symptoms of infection, and step-by-step guidance on how to remove it from your computer.

What Is Trojan.Rugmi.BB?

Trojan.Rugmi.BB is a type of malicious software, commonly referred to as a Trojan, designed to compromise the security of computer systems. Trojans are known for their ability to disguise themselves as legitimate programs, making them difficult to detect without proper security software. The name Trojan.Rugmi.BB suggests it is a variant within a broader category of Trojan threats, but the specifics of its operation and impact can vary.

How Trojan.Rugmi.BB Operates

Trojans like Trojan.Rugmi.BB typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a wide range of malicious activities, including stealing sensitive information, installing additional malware, providing unauthorized access to the infected system, and disrupting system operation. The exact mechanisms used by Trojan.Rugmi.BB can depend on its specific design and the intentions of its creators.

Symptoms of Infection

Symptoms of a Trojan.Rugmi.BB infection can vary but may include unusual system behavior, such as slow performance, frequent crashes, and unfamiliar programs or icons appearing on the desktop. Users might also notice increased network activity without any apparent cause, pop-ups or unwanted advertisements, and changes to browser settings or homepage. In some cases, the infection might not exhibit noticeable symptoms, making regular system checks with anti-virus software crucial for detection.

How to Remove Trojan.Rugmi.BB

  1. Start your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process and allow you to download necessary tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of Trojan.Rugmi.BB and any related malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the infection was detected. Be cautious and only remove programs you are certain are not needed.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by the malware, such as altered homepages or search engines.
  5. After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.Rugmi.BB from your system requires careful steps to ensure all components of the malware are eliminated. It's essential to stay vigilant and maintain up-to-date security software to prevent future infections. Regularly backing up important data and being cautious when opening emails or downloading software from the internet can also help protect against malware threats. If you are unsure about any part of the removal process, consider seeking help from a professional to ensure your system is completely secure.

Analysis Report

General information

Family Name: Trojan.Rugmi.BB
Signature status: No Signature

Known Samples

MD5: fcc7330c0957138334f26b6d2f94e9e6
SHA1: fff8031bd00ebcae704173ecae252380f110ebdf
SHA256: A552F9FFBD46193F551E04B6190CAA11EB4873EEE957B540237205DEBC28FE76
File Size: 6.18 MB, 6182008 bytes
MD5: eaecb4944745479e5fb7cc1e0ece8294
SHA1: fe4952806382f4823664a786cf109a07a721a27b
SHA256: 2C5D8D029D3C35FABCC6CB60E5001087B638D517B483D3943090869B60BF001A
File Size: 6.18 MB, 6183424 bytes
MD5: 02b16af30cfd90774ab44a9f112e4bb6
SHA1: ff5a3d43b49a98dc4512387a6e09c3a7ea220864
SHA256: 596CFB93DDF7331A382B41A0519792FAE311739521011A52BBFBA864A4A8EAEE
File Size: 5.83 MB, 5825144 bytes
MD5: 9a1317065e715ac97362472657bbbd24
SHA1: 17d5cbbbc322209fdba3d09d872ca61b5659e3d4
SHA256: 830D0BFAB0F6B5B8959B07443AF229A32432A4B9DF823DFC43ECE0659C8E5B3E
File Size: 5.86 MB, 5864448 bytes
MD5: aee6252d4dc3f35da61a755580137044
SHA1: 758d12e19fb0fb158fa05b2bebb579ceb339d62e
SHA256: D2F462D0EE1561DA8CCE7B6CFF43F35CCA51684B15BFEBF338AA3837F8D42F22
File Size: 6.13 MB, 6133880 bytes
Show More
MD5: 21bf5c5f60004eff99cff8c481e086db
SHA1: 937dce8e30cd0344a21174357fad307becebef7e
SHA256: F668FBE017ABE45F6E4ECA98852FE705A1874E15474CBD01FADD7212010CB8A6
File Size: 5.86 MB, 5861376 bytes
MD5: 5e703e46bc4d7b68b0850a5e10bcef25
SHA1: 06e160600b0c7046bf5d5d4393cbbe04f93351a0
SHA256: BE3BEE70A01AB575D9D23FEEA7D8C0D2652E45A9879A108AF13405E6D16E84CC
File Size: 6.15 MB, 6149808 bytes
MD5: a2bb1d04cd66d505d44424cd02ccceca
SHA1: 2664e576605707f4d2be551aa46f8ab357d72d43
SHA256: 60299C97C3BF8F0904A348C84A5D5B1B30223593D21BC6452B2F66A84FDAD098
File Size: 5.82 MB, 5819392 bytes
MD5: ee4e748f40d6808b34bb0361879d5d04
SHA1: 2bbf00a6057b2d4e9dfb3a30984d4b4311d3dfa6
SHA256: C3C451FA65B2A9D0863A02708BB3187630EFF2F42D47B2455F2B53A621EA8BC7
File Size: 5.79 MB, 5790208 bytes
MD5: 8d60d306a5bfd28f10ef922821900b5e
SHA1: af4f82911344951a7fa996e2b3cd98dc927b93a0
SHA256: C950B1CCDCBC1003907D1756DEF88AC886DAD26F03A3588CFD0A9DA8B2447D6A
File Size: 5.79 MB, 5790208 bytes
MD5: 8178a1ca188d04f381e0771421dc8328
SHA1: d9b4bafaedf3b3df3cde559d6050de17b7cdce5c
SHA256: E90D7639A52D10F6B51A752A3A9FC709F838C4C86F0BC313DCC9B1BDDE30BD08
File Size: 5.79 MB, 5790208 bytes
MD5: dd60e1c0e1a8ddc11c4f4c003225713f
SHA1: 31854843867af6e8b0e10fe95ff0c815115012af
SHA256: F9FE8E2ACCB5A7088D473376FC05BE8F8BCD853FFC8A45457F0DCF7D947CEF79
File Size: 5.79 MB, 5790208 bytes
MD5: d292d66905f618b840296da4c65a1e22
SHA1: a262f05eb1ccd567d32dc372a3f0e8c45875ca3d
SHA256: 32DC80FF7B1CF56D292FCA04D9F416341BFF94EAF531D4CB5A1457D3BA0063D4
File Size: 5.79 MB, 5790208 bytes
MD5: 3c0b40c2e7d18c535042402295ba8c40
SHA1: 1d05f5bac7a928f8edf8a981b62234935404fc58
SHA256: 531137C78152E3EFA4A98C2BB59A97B365CD973784DBBBDA253090D8CB758B43
File Size: 6.13 MB, 6133880 bytes
MD5: 75fd08ee66fcdff816d5b8d704cb695d
SHA1: df9c5c400a9e9d248b94fb632b4a2f377faea5b2
SHA256: DE656D2F9F78D64DEC8ADE6F6E0F796701B5193F699211A70B8D3A14F9455419
File Size: 5.79 MB, 5790208 bytes
MD5: f7ff90db67b8b1491a3b1f7d74c82f1c
SHA1: bd70a4677abf6e2ef984239a31b31ca967b04f64
SHA256: 96E073314B4604192497CDB74A833D84D980DCD3658F8FF767B49727045D9E3C
File Size: 5.79 MB, 5790208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name The Qt Company Ltd.
File Description C++ Application Development Framework
File Version
  • 5.13.2.0
  • 5.13.0.0
  • 5.12.12.0
  • 5.12.5.0
  • 5.10.1.0
  • 5.9.9.0
  • 5.9.8.0
  • 5.9.6.0
Legal Copyright
  • Copyright (C) 2017 The Qt Company Ltd.
  • Copyright (C) 2019 The Qt Company Ltd.
  • Copyright (C) 2020 The Qt Company Ltd.
Original Filename
  • Qt5Core.dll
  • Qt5Core_bmg.dll
Product Name Qt5
Product Version
  • 5.13.2.0
  • 5.13.0.0
  • 5.12.12.0
  • 5.12.5.0
  • 5.10.1.0
  • 5.9.9.0
  • 5.9.8.0
  • 5.9.6.0

Digital Signatures

Signer Root Status
The Qt Company Oy Entrust Root Certification Authority - G2 Hash Mismatch
The Qt Company Oy thawte SHA256 Code Signing CA Hash Mismatch

File Traits

  • dll
  • x64

Block Information

Total Blocks: 15,159
Potentially Malicious Blocks: 151
Whitelisted Blocks: 14,990
Unknown Blocks: 18

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.BB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage

8 additional items are not displayed above.

Trending

Most Viewed

Loading...