Threat Database Trojans Trojan.Rugmi.OH

Trojan.Rugmi.OH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,414
Threat Level: 80 % (High)
Infected Computers: 611
First Seen: April 10, 2024
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.OH on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your system's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Rugmi.OH?

Trojan.Rugmi.OH is a type of malware that can infect your system without your knowledge or consent. Trojans are malicious programs that can disguise themselves as legitimate software, making them difficult to detect. They can be used to steal sensitive information, install additional malware, or provide unauthorized access to your system. The name Trojan.Rugmi.OH suggests that it is a Trojan-type threat, but its specific characteristics and behaviors may vary.

How Trojan.Rugmi.OH Operates

Trojan.Rugmi.OH can operate in various ways, depending on its intended purpose. It may be designed to steal login credentials, credit card numbers, or other sensitive information. It can also be used to install additional malware, such as ransomware or spyware, on your system. In some cases, Trojans can create backdoors that allow hackers to access your system remotely, giving them control over your computer and allowing them to perform malicious activities.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.OH infection can vary, but common signs include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing frequently or that your browser is being redirected to suspicious websites. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and monitor your system's behavior.

How to Remove Trojan.Rugmi.OH

  1. Restart your system in Safe Mode with Networking to prevent the malware from loading and to give you access to the internet.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan on your system to detect and remove the Trojan.Rugmi.OH and any other malware that may be present.
  3. Uninstall any suspicious programs or software that you don't recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the Trojan.Rugmi.OH has been completely removed.

Conclusion

Removing Trojan.Rugmi.OH from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable anti-malware tools, you can help ensure that your system is secure and free from malware. It's also essential to practice good cybersecurity habits, such as avoiding suspicious emails and attachments, using strong passwords, and keeping your operating system and software up to date. By taking these precautions, you can reduce the risk of infection and protect your personal data from malicious threats like Trojan.Rugmi.OH.

Analysis Report

General information

Family Name: Trojan.Rugmi.OH
Signature status: Hash Mismatch

Known Samples

MD5: 7572c679d968aed46581a7084047a251
SHA1: b3915727eb27ef2824fe3e3d9a3ff295eff03f2a
SHA256: 00D4484CE04F058B5A22517DBC55E48FB867CB2CDBA52B684CD03461BA29E6DF
File Size: 2.14 MB, 2139648 bytes
MD5: 333f4d4adf3e10eb885b2dc6319bff8d
SHA1: 5ab3ce9e06a5712c4b8dddbd3e42fb775d0de312
SHA256: BEFE0DF365F0E2DC05225470E45FDF03609F098A526D617C478B81AC6BB9147F
File Size: 632.00 KB, 632000 bytes
MD5: 65c8fb1cfa8e62b1418aafb93b3c025b
SHA1: 7a931efedd960c4ac49c76e07e68c099c5badc3a
SHA256: 3A01DFBC5B6739762408427FC1B80B95F5FB2582C38343057BD811880640DF10
File Size: 364.76 KB, 364760 bytes
MD5: 66c2710333db4a3720b2fe534cf68833
SHA1: ddacd82f14e7d1e54eaa44439cf5bc8a4b063972
SHA256: A11474AB94009599E6294A4D0754C61891A8603789082B78A104E7B74C080BDA
File Size: 2.42 MB, 2417832 bytes
MD5: 2166d6d66c3f19974c3920b7ce174d24
SHA1: 19c2f7a425a55eb62fc0ed3fbf40408dc348102c
SHA256: 9DD604134B7B3813FB3BBA03F9B5CCAE0A6C3FDDD56EF6EF4091AD238808504C
File Size: 1.11 MB, 1109760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • DataNumen, Inc.
  • iTop Inc.
  • Nokia Corporation and/or its subsidiary(-ies)
  • The curl library, https://curl.haxx.se/
  • VMware, Inc.
File Description
  • C++ application development framework.
  • DZIPR DLL
  • libcurl Shared Library
  • Product Statistics
  • VMware Tools Runtime Library
File Version
  • 10.0.12.325
  • 7.60.0
  • 4.7.0.0
  • 4.0.0.0
  • 3.0.0.6408
Internal Name
  • DZIPR.DLL
  • libcurl
  • vmtools
Legal Copyright
  • ? 1996 - 2018 Daniel Stenberg, <daniel@haxx.se>.
  • Copyright (C) 2010 Nokia Corporation and/or its subsidiary(-ies).
  • Copyright 2001 to 2023 by DataNumen, Inc. All rights reserved.
  • Copyright © 1998-2016 VMware, Inc.
  • © iTop Inc. All rights reserved.
Legal Trademarks iTop Inc.
License https://curl.haxx.se/docs/copyright.html
Original Filename
  • DZIPR.DLL
  • libcurl.dll
  • ProductStatistics3.dll
  • QtCore4.dll
  • vmtools.dll
Product Name
  • DZIPR DLL
  • Product Statistics
  • Qt4
  • The curl library
  • VMware Tools
Product Version
  • 10.0.12 build-4448491
  • 7.60.0
  • 4.0.0.0
  • 3.0

Digital Signatures

Signer Root Status
AOMEI International Network Limited COMODO RSA Certification Authority Hash Mismatch
ORANGE VIEW LIMITED DigiCert High Assurance EV Root CA Hash Mismatch
DataNumen, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
AOMEI International Network Limited GlobalSign CodeSigning CA - G3 Hash Mismatch
VMware, Inc. VeriSign Class 3 Public Primary Certification Authority - G5 Hash Mismatch

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 3,943
Potentially Malicious Blocks: 73
Whitelisted Blocks: 3,870
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.FI
  • Rugmi.IFB
  • Rugmi.OE
  • Rugmi.PG

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b3915727eb27ef2824fe3e3d9a3ff295eff03f2a_0002139648.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5ab3ce9e06a5712c4b8dddbd3e42fb775d0de312_0000632000.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7a931efedd960c4ac49c76e07e68c099c5badc3a_0000364760.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ddacd82f14e7d1e54eaa44439cf5bc8a4b063972_0002417832.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\19c2f7a425a55eb62fc0ed3fbf40408dc348102c_0001109760.,LiQMAxHB

Trending

Most Viewed

Loading...