Trojan.Slugin.B
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 12,054 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 287 |
| First Seen: | July 12, 2021 |
| Last Seen: | July 22, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Slugin.B on your system indicates a potential security threat that requires immediate attention. Trojan horses, like Trojan.Slugin.B, are malicious programs that can compromise the security and integrity of your computer. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.
Table of Contents
What Is Trojan.Slugin.B?
Trojan.Slugin.B is a type of malware that disguises itself as a legitimate program to gain unauthorized access to your computer. Once inside, it can cause significant damage, including data theft, system crashes, and the installation of additional malware. The name Trojan.Slugin.B suggests that it is a Trojan-type threat, but its specific characteristics and behavior may vary. It is crucial to approach this threat with caution and follow a systematic removal process to ensure your system's safety.
How Trojan.Slugin.B Operates
Trojan.Slugin.B, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as opening malicious email attachments, downloading infected software, or visiting compromised websites. Once installed, the Trojan can create backdoors for remote access, allowing attackers to control your computer, steal sensitive information, or use your system for malicious activities. The exact mechanisms of Trojan.Slugin.B might not be fully understood without specific analysis, but its potential for harm is clear.
Symptoms of Infection
The symptoms of a Trojan.Slugin.B infection can vary, but common signs include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You might also notice unfamiliar programs or toolbars in your browser, changes in your homepage, or an increase in spam emails. Sometimes, the infection may not exhibit noticeable symptoms, making it difficult to detect without proper scanning tools. If you suspect that your system is infected, it is vital to act quickly to minimize potential damage.
How to Remove Trojan.Slugin.B
- Restart your computer in Safe Mode with Networking to prevent the malware from loading and to give you a cleaner environment for removal.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove Trojan.Slugin.B and any associated malware.
- Uninstall any suspicious programs that you do not recognize or that were installed around the time you noticed the infection. Be cautious and only remove programs you are sure are safe to uninstall.
- Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
- After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.
Conclusion
Removing Trojan.Slugin.B requires careful and systematic steps to ensure that your system is thoroughly cleaned and protected. It is also crucial to adopt preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening emails or downloading files from the internet. By understanding the nature of Trojan horses and taking proactive steps, you can significantly reduce the risk of future infections and maintain the security and integrity of your computer.
Analysis Report
General information
| Family Name: | Trojan.Slugin.B |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
5b0ee1b06f1a90b3156ea7c1a5b9920e
SHA1:
8015e2839c5c0c0329e92893627d664a43061426
SHA256:
C1877A055E3FA8A69EFDF482EEA0C1F9593678F17930155F7585C62BAFEC9506
File Size:
483.81 KB, 483811 bytes
|
|
MD5:
98b99a210a6e6a886050b759eec3506d
SHA1:
a66f8e71f682bbed94ae629408eb3b7726cfaf37
SHA256:
D2EEE0713FC55D3B110582B4A68369300EBD2A59B473E7EE50AC6FF65D6968E7
File Size:
1.03 MB, 1031139 bytes
|
|
MD5:
eb4acbaedd365a94ac01d44934bdebde
SHA1:
4bfce9a75cdf5a2ebb88b80c72468aaca8c814c9
SHA256:
6135A5ABE346A3AF1757998C92AFF58732468333B6C4A12714DB761703E3454B
File Size:
198.14 KB, 198144 bytes
|
|
MD5:
414731c8de91b6e921284dea4cf673ba
SHA1:
171c4b9b8d00ed8159054f34be6531fff23d3e0a
SHA256:
6788E3D15D5F5432C9F6B8FFCE17AC581A90F408F910913609D2C28725E9E0E5
File Size:
199.03 KB, 199031 bytes
|
|
MD5:
8375e7197646f957200d4689661da934
SHA1:
acb11bc9eb8a6127b146573e43977f85450c3b00
SHA256:
51A98D051B16B7026DC517282BF34FC015BD5D2F7A36749CBE8B5D592D3314D9
File Size:
848.36 KB, 848355 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename | GP4_Install_Startup.EXE |
| Product Name |
|
| Product Version |
|
File Traits
- 2+ executable sections
- big overlay
- BINinO
- HighEntropy
- Installer Manifest
- Installer Version
- MZ (In Overlay)
- nosig nsis
- No Version Info
- SusSec
Show More
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 513 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 507 |
| Unknown Blocks: | 6 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\users\user\appdata\roaming\wplugin.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\windows\system.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\windows\wplugin.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows\currentversion\policies\system::enablelua | RegNtPreCreateKey | |
| HKCU\software\user914\1214104697::1919251317 | + | RegNtPreCreateKey |
| HKCU\software\user914\1214104697::-456464662 | RegNtPreCreateKey | |
| HKCU\software\user914\1214104697::1462786655 | RegNtPreCreateKey | |
| HKCU\software\user914\1214104697::-912929324 | # | RegNtPreCreateKey |
| HKCU\software\user914\1214104697::1006321993 | ½ | RegNtPreCreateKey |
| HKCU\software\user914\1214104697::-1369393986 | http://lpbmx.ru/logos.gif http://macedonia.my1.ru/mainh.gif ht | RegNtPreCreateKey |
| HKCU\software\user914\1214104697::549857331 | �g;�_��6̚��6�zu)����#�]��^t��A�P�Av�h�m,�:,%O4��[�� | RegNtPreCreateKey |
Show More
| HKCU\software\user914::u1_0 | ⠺첖 | RegNtPreCreateKey |
| HKCU\software\user914::u2_0 | ᖍ | RegNtPreCreateKey |
| HKCU\software\user914::u3_0 | 晁ă | RegNtPreCreateKey |
| HKCU\software\user914::u4_0 | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Process Manipulation Evasion |
|
| Anti Debug |
|
| User Data Access |
|