Threat Database Trojans Trojan.Rugmi.LDB

Trojan.Rugmi.LDB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,061
Threat Level: 80 % (High)
Infected Computers: 56
First Seen: September 20, 2025
Last Seen: June 4, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.LDB on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Rugmi.LDB?

Trojan.Rugmi.LDB is a type of malware that can infiltrate your system through various means, such as downloading infected software, opening malicious email attachments, or visiting compromised websites. Once inside, it can perform a range of malicious activities, including data theft, system compromise, and disruption of normal computer functions. The name "Trojan.Rugmi.LDB" suggests that it is a Trojan-type threat, but it is crucial to note that the specific characteristics and behaviors of this malware are not well-documented, making it essential to rely on general guidance for removal.

How Trojan.Rugmi.LDB Operates

Trojan.Rugmi.LDB, like other Trojans, operates by exploiting vulnerabilities in your system or using social engineering tactics to deceive users into installing it. Once installed, it can create backdoors for remote access, allowing attackers to control your system, steal sensitive information, or use your computer as a botnet for malicious activities. The exact mechanisms of Trojan.Rugmi.LDB are not specified, but it is known that Trojans can be highly adaptable and may evolve over time to evade detection and removal.

Symptoms of Infection

Identifying a Trojan.Rugmi.LDB infection can be challenging, as it may not exhibit obvious symptoms. However, common signs of a Trojan infection include slow system performance, frequent crashes, unexpected pop-ups, and unusual network activity. You might also notice that your antivirus software is disabled or that certain programs are not functioning correctly. If you suspect that your system is infected with Trojan.Rugmi.LDB, it is vital to take immediate action to mitigate the threat.

How to Remove Trojan.Rugmi.LDB

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of Trojan.Rugmi.LDB.
  3. Uninstall any suspicious programs that you have recently installed, as they may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the Trojan may have altered.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Rugmi.LDB from your system requires careful and immediate action. By following the steps outlined above and maintaining vigilance in your online activities, you can protect your system from future infections. It is also essential to keep your operating system, software, and security tools up to date to prevent exploitation of known vulnerabilities. Remember, the key to securing your system is a combination of awareness, proactive security measures, and prompt response to detected threats.

Analysis Report

General information

Family Name: Trojan.Rugmi.LDB
Signature status: Hash Mismatch

Known Samples

MD5: c245cef8af53cdff9c6b7786563ad618
SHA1: 6baa9ac4bcad3ed5f4609d56edd8ebcbb4f279b6
SHA256: AD38ED196CA91B4B34284A4CF3258C40176C60D6C078786EF58C45A88E772D8F
File Size: 1.27 MB, 1270184 bytes
MD5: 8c7f532af958b2aecde2e90fbf58f185
SHA1: 2e3e0446fb53b65e45f0ece9c716940c3d8e4cbf
SHA256: 716E9296ACB22B1815B0920849FF6EAF4A592FEBA179039F64F2D19A3ABE5763
File Size: 154.62 KB, 154624 bytes
MD5: 029980f5e584b3d941d4c8c7f94eb8dd
SHA1: 8051f2f00519a043254f359404c66376d1ffda42
SHA256: 58DE8F7B9823D00CC2FD67467FB8044DC94D5F7CDF585381E7AF8A7D93443B7C
File Size: 1.51 MB, 1508400 bytes
MD5: 3f65c803c972afef86349f63e1f4f515
SHA1: 7301e725c1e54a5bd33e45e37c0a0221931af927
SHA256: 92B9F44DA00482F270F992414211B4274CCF7D0AD10EE64C9323336DAC96BBC6
File Size: 303.57 KB, 303568 bytes
MD5: d6215a72dbc0a46ddc70df45cb249b44
SHA1: 2917c838cf6f141cfca055ab5eb9079f0de5f912
SHA256: C667804C6CF8026ED357792A64311E8C5EEF65A9C4728812D70E963D5CFACBB2
File Size: 2.50 MB, 2501736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • BugSplat, LLC
  • Microsoft Corporation
File Description
  • Crash Handling Module
  • Crash reporting module, BugSplat.DLL
  • Microsoft Instrumentation Engine
  • Microsoft® Disassembler
File Version
  • 15.1.0.2022032203
  • 14.44.35207.1
  • 3, 3, 1, 0
  • 1.4.0.2
Internal Name
  • BugSplat.DLL
  • CrashRpt
  • MicrosoftInstrumentationEngine_x86
  • MSVCDIS140.DLL
Legal Copyright
  • Copyright 2003-2013 The CrashRpt Project Authors
  • Copyright BugSplat, LLC (C) 2015
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation.
Original Filename
  • BugSplat.DLL
  • CrashRpt.dll
  • MicrosoftInstrumentationEngine_x86.dll
  • MSVCDIS140.DLL
Product Name
  • BugSplat Dynamic Link Library
  • CrashRpt
  • Microsoft® Visual Studio®
Product Version
  • 15.1.0.2022032203
  • 14.44.35207.1
  • 3, 3, 1, 0
  • 1.4.0.2
Special Build 0

Digital Signatures

Signer Root Status
Planestate Software AB COMODO RSA Code Signing CA Hash Mismatch
BugSplat LLC Go Daddy Secure Certification Authority Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 7,027
Potentially Malicious Blocks: 3,310
Whitelisted Blocks: 3,717
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x x 0 0 x x x x x x x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 2 x x x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 1 x x x x 0 0 x x x 0 0 x x 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 x x x x 0 x x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 2 0 x 0 0 0 x 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 2 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x x x 0 x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 x x 0 x 0 0 x 0 x 0 0 0 x x x 0 0 0 0 1 1 0 x x 0 x x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 1 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x x x x x x 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x x x x 0 x x x x 0 x x 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 x x 0 0 0 0 0 x x 0 0 1 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x x x x 0 x 0 x 0 x x x 0 0 0 x x x x x x x 0 x x 0 0 0 x x x x 0 0 x x x 0 1 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 x x 0 0 0 x x x 0 0 0 x 0 x x x x x 0 x x 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x x 0 0 x 0 x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x 0 0 x 0 x x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 0 0 x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x 0 x x 0 x x 0 x x 0 x x x x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 x x 0 0 x x x x 0 0 x 0 x x 0 0 0 0 0 x x x x 0 x 0 0 0 0 x x 0 0 x x x x x x x x x x x x x 0 x x 0 x x x x x x x x x x 0 0 0 x x x x 0 x x x x x 0 x x x x x x x x x 0 x x x x x 0 x x 0 x x x 0 x x x x x 0 x x 0 0 0 0 x x x x x 0 x 0 x x 0 x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x 0 x x 0 x x x 0 0 x 0 x x 0 x x x 0 0 0 0 x x x 0 0 0 x x x x 0 0 0 0 x 0 0 x x x x 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x 0 x x 0 x 0 0 0 0 x 0 x 0 x x x 0 0 0 1 0 x 0 0 x x 0 0 0 x 0 x x x 0 x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 1 x x x x x x x x x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 x x x 0 x x x x x x x x x 0 x x 0 0 x 0 x 0 x 0 x 0 0 x x x x x x 0 0 0 0 0 x x x x x x 1 x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 0 x x x x x 0 0 x x x x x x 0 x x x x 0 x x x x x x 0 0 x x x x x x x 0 x 0 x x x x 0 x x x x 0 0 x 0 0 x x x x 1 x 0 0 x x x x x x 0 x 0 x x x x 0 0 0 0 0 x x 0 0 0 x x 0 0 x x x x x 0 x 0 x x 0 0 x 0 0 x x x x x 0 x 0 x 0 x x 0 x x x x 0 x x x 0 x x x x x x 0 x 0 x x 0 0 x 0 0 x x x x x 0 x x x 0 x 0 x x 0 0 0 0 0 x x x 0 x x x x x x 0 0 x x 0 0 x 0 0 0 x x x 0 x x 0 x x x x x x x x 0 x x x x 0 0 x x x 0 x 0 x 0 x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 x x x 0 0 0 0 x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x 1 0 0 0 0 x x x x 0 x 0 x x x x 0 x x x x x 0 x 0 x 0 x x 0 x x x x x x x 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x x 0 0 0 x x 0 x x x 0 x x x x x 0 0 x x x x x 0 0 x 0 0 x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 x x x x 0 0 x x 0 x 0 x x x x x 0 0 x x x 0 0 x x x 0 x x x x x x 0 0 0 x x 0 x x x x x x x x x x x x 0 0 x x x x x x 0 0 0 0 0 x 0 x 0 x x x 0 x x x x x 0 0 0 0 x x x x x 0 x x x x x 0 x x x x 0 x x 0 x x 0 x x 0 x x 0 x 0 0 x x x x x x 0 x x x x 0 x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 x x x 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 x x 0 0 0 x x x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x 0 0 x x 0 x x x x x 0 0 0 x x 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x x x x x x x x x x 0 0 0 x x x x x x 0 x x x 0 0 x x 0 0 x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.GI
  • Rugmi.LDB
  • Rugmi.OO
  • Rugmi.TB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6baa9ac4bcad3ed5f4609d56edd8ebcbb4f279b6_0001270184.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2e3e0446fb53b65e45f0ece9c716940c3d8e4cbf_0000154624.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8051f2f00519a043254f359404c66376d1ffda42_0001508400.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7301e725c1e54a5bd33e45e37c0a0221931af927_0000303568.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2917c838cf6f141cfca055ab5eb9079f0de5f912_0002501736.,LiQMAxHB

Trending

Most Viewed

Loading...