Threat Database Trojans Trojan.Rugmi.HA

Trojan.Rugmi.HA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,804
Threat Level: 80 % (High)
Infected Computers: 126
First Seen: August 12, 2025
Last Seen: July 12, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.HA on your system indicates a potential security threat that requires immediate attention. Trojan-type threats are known for their ability to disguise themselves as legitimate programs, making them difficult to detect and remove. In this report, we will provide you with information on what Trojan.Rugmi.HA is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is Trojan.Rugmi.HA?

Trojan.Rugmi.HA is a type of malware that can compromise the security of your system by allowing unauthorized access to your computer. Trojans are designed to look like legitimate software, but they can cause significant harm by stealing sensitive information, installing additional malware, or providing a backdoor for hackers to access your system. The name Trojan.Rugmi.HA suggests that it is a Trojan-type threat, but its specific capabilities and intentions are not immediately clear without further analysis.

How Trojan.Rugmi.HA Operates

Trojan.Rugmi.HA, like other Trojans, operates by exploiting vulnerabilities in your system or by tricking you into installing it. Once installed, it can communicate with its command and control servers to receive instructions, which may include stealing data, installing additional malware, or using your system for malicious activities. Trojans can also disguise themselves as system files or legitimate programs, making them hard to detect without proper security software.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.HA infection can vary, but common signs include unusual system behavior, such as slow performance, frequent crashes, or pop-ups. You might also notice that your browser settings have been changed without your permission, or that new, unfamiliar programs have been installed. In some cases, you might not notice any symptoms at all, which is why regular system scans with reputable security software are crucial.

How to Remove Trojan.Rugmi.HA

  1. Enter Safe Mode with Networking to prevent the Trojan from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the Trojan's ability to operate.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing Trojan.Rugmi.HA.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the Trojan was detected. Be cautious and only remove programs you are sure are not necessary for your system's operation.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another scan to ensure that the Trojan and any associated malware have been successfully removed.

Conclusion

Removing Trojan.Rugmi.HA requires careful and immediate action to prevent further damage to your system and to protect your sensitive information. By following the steps outlined above and maintaining good security practices, such as regularly updating your security software and being cautious with emails and downloads, you can help protect your system from future threats. Remember, prevention is key, and staying informed about the latest threats and how to mitigate them is crucial in the ever-evolving landscape of cybersecurity.

Analysis Report

General information

Family Name: Trojan.Rugmi.HA
Signature status: Hash Mismatch

Known Samples

MD5: 869bc39dd7c87a63bbb1613f2dbfc323
SHA1: e3fe962200dd964c79b909da9747128ed047ce99
SHA256: 37A84AF70FC79265FFE9AA45FD9BAFD092858EEA729FFB1F4D8E714C60674770
File Size: 603.38 KB, 603376 bytes
MD5: a8bee658e80c3a2cb7951b0734ca79cb
SHA1: 28e3de30632d37e397be8125603d7ed6c3740037
SHA256: AB97432D8F502152E0FC9AB448EB22827BDCE19577B976B6455D00E3A0939F64
File Size: 614.40 KB, 614400 bytes
MD5: 335535e7e1a6764462281634321d73bc
SHA1: 40ff6ede8bb467fce0d0c8403b6962592809e020
SHA256: A5EC3263A3F937E4A674BA1BC221058C8C330E13195FC9729D63995D3A3F35B0
File Size: 603.38 KB, 603376 bytes
MD5: dcc7999a2f91dde547836f875b427584
SHA1: 0f727dd29987fc01db85741fc4fa01f6ea38e1d8
SHA256: 3DB406D9FB6BE578DDC32184E680B1B4F5EC0D9B94E12204912AD2B10CD22EF4
File Size: 603.38 KB, 603376 bytes
MD5: 2ec224903d989b3a8f8c575518254d21
SHA1: c4c77e9b9b4d1d5dbdc33000910a89f8da67899e
SHA256: 25EF89B072E18B2781F6FE07B167934C7B7A01630E5F0B388358F40BEE1A5789
File Size: 603.38 KB, 603376 bytes
Show More
MD5: 7bd0dfa3723e065bedb053d1659be134
SHA1: 46872e351c7efdb4eb1c50e3078bb2bf0b4debac
SHA256: 019FDC2A35922B47C887D94D5E0513818DD83E916AE504AAE93BF688388701BB
File Size: 603.38 KB, 603376 bytes
MD5: ea458eb88cb18c6e02899fe51d025c96
SHA1: f89df599bc80e3b8a71c58f2a70de4277fed4335
SHA256: 4181A4BD3AF025815CD3ADD574E8395A7882866A385D778FD26F25062B43D3E6
File Size: 603.38 KB, 603376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
AOMEI International Network Limited Sectigo Public Code Signing Root R46 Hash Mismatch
AOMEI International Network Limited Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • ntdll
  • x86

Block Information

Total Blocks: 1,520
Potentially Malicious Blocks: 631
Whitelisted Blocks: 887
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x 0 x x x x x x x x 0 x x x 0 0 x x x 0 0 x x 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x x 0 x x 0 x x 0 x x 0 x x x x x 0 x x x 0 x x x 1 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x 0 0 x 0 0 x x x 0 x x 0 x 0 0 x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 x x x x 0 0 x x x x x x x x x 0 0 x 0 0 0 x x x x x x x x x x x 0 x x x 0 x 0 x x x x x x 0 0 x x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x x x 0 0 0 x x x x x x x x 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 x 0 0 x x x 0 x 0 x x 0 x 0 x x x x x 0 x x x x x x x 0 0 0 x 0 x 0 x x 0 x x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x 0 x 0 x x 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 0 x x 0 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x x 0 x x x x x x x x x x x x x 0 0 x 0 x 0 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x x x x x x x x 0 0 x x x x x x x 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x x x 0 0 x x x x x 0 x x x x 0 x x 0 0 x 0 0 x x x 0 x 0 0 x 0 x x x x x x x x x x x 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 x x 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x 0 x x x x x x x 0 x 0 x x 0 0 x 0 x 0 0 0 x x x 0 x 0 x x x x x 0 0 0 0 x 0 x 0 x x x x x x 0 x 0 0 x 0 x x 0 0 x x 0 x 0 x x 0 0 x x x 0 x x 0 x x x x 0 0 x x x 0 x x x 0 0 x x 0 x 0 0 x x x x 0 x 0 0 x x 0 0 0 x 0 0 x x x 0 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 x 0 0 0 0 x 0 x x x x x x 0 x 0 0 0 0 x x 0 0 0 0 x 0 0 0 x x x 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x 0 x x 0 x 0 0 x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x x 0 x x 0 x 0 x 0 x 0 0 x x x 0 0 x x 0 0 x 0 0 x x x x x x x x 0 0 0 0 x 0 0 0 x x 0 0 0 x 0 x 0 x 0 0 x x x x x x x x x 0 x 0 0 x x x 0 x 0 0 0 0 0 x x x 0 x 0 0 0 0 0 x x x 0 x 0 0 x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x 0 0 0 0 0 x x 0 0 0 x x 0 0 x x x x x x 0 0 0 x x x x x x x x x x x 0 0 0 x x 0 x x x 0 x x x x x x 0 x x 0 0 x 0 x x 0 x x 0 0 0 x x x 0 0 x x 0 0 x 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 x 0 0 x 0 0 0 0 0 x 0 0 x x x 0 1 x x x 0 x 0 0 x 0 0 x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 x 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 ? ? 2 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\windows\syswow64\log\reg.log Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e3fe962200dd964c79b909da9747128ed047ce99_0000603376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\28e3de30632d37e397be8125603d7ed6c3740037_0000614400.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\40ff6ede8bb467fce0d0c8403b6962592809e020_0000603376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0f727dd29987fc01db85741fc4fa01f6ea38e1d8_0000603376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c4c77e9b9b4d1d5dbdc33000910a89f8da67899e_0000603376.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\46872e351c7efdb4eb1c50e3078bb2bf0b4debac_0000603376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f89df599bc80e3b8a71c58f2a70de4277fed4335_0000603376.,LiQMAxHB

Trending

Most Viewed

Loading...