Threat Database Trojans Trojan.Lumma.G

Trojan.Lumma.G

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,626
Threat Level: 80 % (High)
Infected Computers: 4
First Seen: August 27, 2024
Last Seen: May 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Lumma.G on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Trojan.Lumma.G?

Trojan.Lumma.G is identified as a Trojan-type threat. Trojans are malicious programs that can sneak onto your computer and cause harm without your knowledge. They can be disguised as legitimate software, making them difficult to detect. The name itself does not directly imply a specific malware family, but its classification as a Trojan suggests it is designed to allow unauthorized access to your computer or to disrupt its operation.

How Trojan.Lumma.G Operates

Trojan.Lumma.G, like other Trojans, operates by exploiting vulnerabilities in your system's security. Once inside, it can perform a variety of malicious activities, including but not limited to, stealing sensitive information, installing additional malware, or providing a backdoor for remote access by attackers. The exact mechanisms can vary, but the primary goal is to compromise your system's integrity and your privacy.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. However, common indicators include unusual system behavior such as slow performance, frequent crashes, or pop-ups and unwanted software installations. Sometimes, you might notice that your browser settings have been altered or that you are being redirected to unwanted websites. It's also possible for the infection to remain asymptomatic for a period, making regular system checks crucial.

How to Remove Trojan.Lumma.G

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and make it easier to remove. To do this, restart your computer and press the key to access your boot menu (this varies by manufacturer but is often F12, F2, or Del). Select the option to boot into Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or that you do not recognize. Be cautious and only remove programs you are sure are not needed.
  4. Reset Your Browsers: Resetting your browsers (Chrome, Firefox, Edge, etc.) to their default settings can help remove any malicious extensions or settings that the Trojan might have installed. You can usually find this option in the browser's settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that the Trojan and any associated malware have been successfully removed.

Conclusion

Removing Trojan.Lumma.G from your system requires careful and methodical steps to ensure that all components of the malware are eliminated. It's crucial to stay vigilant and regularly check your system for signs of infection. Keeping your operating system, software, and security tools up to date can also help protect against future infections. Remember, prevention is key, but when infections do occur, acting quickly and using the right tools can minimize the damage and restore your system's security and performance.

Analysis Report

General information

Family Name: Trojan.Lumma.G
Signature status: Self Signed

Known Samples

MD5: 1f61c03c95c3bd2b431d21457850484a
SHA1: a0ba6c658d188527064bf796ecd54a6dc723f2fc
SHA256: 96B9BCB13C490E6E6990DD4C70186F8AB835FC6890CA2DDC1FCAA55482CCD0D3
File Size: 4.41 MB, 4405352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name EVERYS
File Description EVERYS WpMail
File Version 3.16
Internal Name WPMAIL
Legal Copyright Copyright © EVERYS 1996-99
Original Filename WPMAIL.EXE
Product Name EVERYS WpMail
Product Version 3.16

Digital Signatures

Signer Root Status
EVERYS SSL.com Code Signing Intermediate CA ECC R2 Self Signed

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 8,137
Potentially Malicious Blocks: 96
Whitelisted Blocks: 5,173
Unknown Blocks: 2,868

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? 1 1 ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? x ? 0 ? ? 0 x ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? x 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? x 1 x 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? x x ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 ? x ? 0 0 0 ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 x x ? 0 0 0 x x ? ? ? ? ? ? ? ? 0 0 0 ? x ? x ? ? x ? ? 0 ? ? 0 0 x ? ? ? 0 ? ? ? 0 ? ? 0 x ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? x ? 0 0 0 0 0 ? 0 x ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? x ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? x x ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 x ? x x 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x 0 0 0 x 0 0 0 0 0 x 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 x ? ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 0 0 ? 0 ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? x 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? x 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 x ? x ? 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? x ? ? 0 0 ? ? ? x ? x ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? 0 0 ? ? 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 0 ? ? 0 ? ? 0 0 ? 0 ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? 0 x ? ? ? ? x ? ? ? ? ? 0 ? ? ? 0 ? x 0 ? ? 0 ? ? ? 0 x ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? ? x 0 x x x 0 x 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? x ? 0 0 0 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x x 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\tele.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\wpmail.snd Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...