Threat Database Trojans Trojan.Rugmi.DB

Trojan.Rugmi.DB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,080
Threat Level: 80 % (High)
Infected Computers: 428
First Seen: October 21, 2025
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.DB on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with an understanding of what this threat is, how it operates, the symptoms you might experience, and most importantly, how to remove it from your computer.

What Is Trojan.Rugmi.DB?

Trojan.Rugmi.DB is identified as a Trojan-type threat. Trojans are malicious programs that can cause harm to your computer system. They are often disguised as legitimate software but are designed to allow unauthorized access to your computer, steal sensitive information, or disrupt system operations. The name "Trojan.Rugmi.DB" itself does not specify a known malware family, but its classification as a Trojan indicates its potential to cause significant damage.

How Trojan.Rugmi.DB Operates

Trojan.Rugmi.DB, like other Trojans, is likely designed to operate stealthily, attempting to evade detection by security software. Once installed on your system, it can create backdoors for remote access, allowing attackers to control your computer, steal personal data, or use your system for malicious activities such as spreading spam or malware. Trojans can also download and install additional malware, further compromising your system's security and performance.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, there are several symptoms that may indicate your system is infected with Trojan.Rugmi.DB or similar malware. These include unusual system behavior, such as unexpected crashes or freezes, slow system performance, unfamiliar programs or icons on your desktop, unexpected changes to your system settings, and increased network activity without apparent reason. Additionally, you might notice that your antivirus software is disabled or that you are unable to update your security programs.

How to Remove Trojan.Rugmi.DB

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and make it easier to remove. To do this, restart your computer and press the key to access your boot menu (this key varies by computer manufacturer but is often F8, F12, or Esc). Select Safe Mode with Networking and let your computer boot up.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your tool is updated with the latest definitions before scanning to increase the chances of detecting and removing the Trojan.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or unfamiliar. Be cautious and only uninstall programs you are sure are not needed.
  4. Reset Your Browsers: Trojans can affect your web browsers, changing settings or installing malicious extensions. Resetting Chrome, Firefox, Edge, or any other browser you use can help remove these changes. Each browser has a reset option in its settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another full scan with your anti-malware tool to ensure that the Trojan and any associated malware are fully removed.

Conclusion

Removing Trojan.Rugmi.DB requires careful and systematic steps to ensure your system is thoroughly cleaned and protected. By following the guidance provided, you can significantly reduce the risk of further damage from this Trojan. It's also crucial to adopt preventive measures, such as keeping your operating system and software up to date, using strong antivirus protection, avoiding suspicious downloads, and being cautious with email attachments and links. Remember, vigilance and proactive security practices are key to protecting your digital assets from evolving cyber threats.

Analysis Report

General information

Family Name: Trojan.Rugmi.DB
Signature status: Hash Mismatch

Known Samples

MD5: 912f0680c26a147dddde13fefe0bd213
SHA1: 812b46837c500271ad0a9ccb6f5206c4c2dc5bcd
SHA256: 495C68ACBCDA745A7716B87B40F0985598CE5B58B919A85A1609BCEFD59C8DDE
File Size: 855.82 KB, 855824 bytes
MD5: e1ec6174ce756027023947b9968cd1ab
SHA1: 4087f93b953d5f9be7ed9f52dd6596e7b1ccfc33
SHA256: 2569214DE4E1C87645F2A7ABBF4E83756A35BE571C06B87CF02F9B9CBD28AACF
File Size: 855.82 KB, 855824 bytes
MD5: 9b21dffc85d6bd8704652fefd00b808a
SHA1: 4a43cf84c8478770d26dab269ec718ef7035dc77
SHA256: 95E1085EDC3D38A989352D00C7725468488E8A9FE4F32E49038E5F23C5AB0527
File Size: 855.82 KB, 855824 bytes
MD5: 66fbd73fdee1030ebc09199c109c5789
SHA1: a80b681b5d4f7bf5a33af5da44913bc532813ecb
SHA256: F5879CBC6F3CE5A145775C8D8F5ECD4CE83F1CE38F02171A030443C501FA794A
File Size: 855.82 KB, 855824 bytes
MD5: c948882aa494c03b6d37617e1a84a8b5
SHA1: 5072f25df2e8068678769c47b7b8e33abfe80c61
SHA256: BE533AE86F30632ECBFA1EB56F3812BA309365CC744D1419A3CACE17BD4C4B22
File Size: 855.82 KB, 855824 bytes
Show More
MD5: f69b9bffa533ce9e92dd75ecd6ba1b4b
SHA1: 38e70d9da920ac0030ad738822e83508167d350d
SHA256: 73860F84DB2BDA6F517B17F63528C3B5BD9FD68D824CBC8D87CC0B9DF99CDD8C
File Size: 855.82 KB, 855816 bytes
MD5: 943293d432eba6c00330b56ff8cda5a7
SHA1: 5ca9e13a06b89bb4e84720c76990fa109cc62b80
SHA256: 8A59A8491140F55C36555589ED4B7182206E1AB756094B018B71F0BD8B870C3A
File Size: 855.82 KB, 855824 bytes
MD5: 200f4cfd829b351b3e159019b5080be7
SHA1: 7b8108dd681c98083cf8d43eea66654b2bbff4ee
SHA256: 46D42C075E39F3DFB7414273F4297CE0607D1EBD8AA556AD7D3D44EB42A111C9
File Size: 855.82 KB, 855824 bytes
MD5: dd7490a4fa58af0a2bd5c5c04520ee37
SHA1: 57ef28812f0f9023cb48ade29977692f8ec1a395
SHA256: 99FC85886DFF03968E01846FC7545DE47C25861983502DD48F2E14BD2FAAFD14
File Size: 855.82 KB, 855824 bytes
MD5: ea013c879b2ff0045de99fab3fa01904
SHA1: a898d73802efaf0db0ed64b5f3ebe21e31bedd86
SHA256: D2753784E0B81E235C6A584C2D2D158D99DB2B37052EE1B6EAC4685540255605
File Size: 855.82 KB, 855824 bytes
MD5: 7524406b7c48daa4f55fa0d3868a65f6
SHA1: e0dc760160221bfb7c8ba36403d089eb740718c5
SHA256: E94A627F9B102245352108B320762E7F65FE68F9653F3AC00CD55E56D31A23E7
File Size: 855.82 KB, 855824 bytes
MD5: 5e367efeedb6ad214cc857340b627060
SHA1: fddd052a8feff8b20be199557195ef80fc8f05ce
SHA256: 4F8D0AD326C2292F23373B458B60C4F1754C02B5923D5C583B56FDEA85797AE3
File Size: 855.82 KB, 855824 bytes
MD5: 49e2d217b3092bf77e5ff09168a2ed2e
SHA1: 360c9a30a78fed56ba46bfb418f4f3ef8e1a8a26
SHA256: A43064A015FD60FEFF0A80EEB883783D405FE146782DEAEC29B259AAB4B1C4E6
File Size: 855.82 KB, 855816 bytes
MD5: 737697f1fabfb135620ae815dac277fc
SHA1: 8d355e267565462aaa7af69e8f36e728735270d4
SHA256: 572CC02403CB2B772A6F91E9F1EF95297E9CE1C7546605E00A4CFD1084099DC4
File Size: 855.82 KB, 855824 bytes
MD5: 7922243c3c0ca209d44e14221651fe80
SHA1: aca3b207116659d313e3ac17fcec689515cecdd3
SHA256: B3764FDE11DAF898322493863D1C0ABD6576B09973C3B95AC6F2EB04FC3F9A82
File Size: 855.82 KB, 855824 bytes
MD5: 662a0d1e21d0d02db6527a52ba9a9fb9
SHA1: 15327f5a927a19fde10c8543b4212bbcdf7c091f
SHA256: 58CB067883013487AEB18115D174E41699DB2EF84343F3478A75F6D2A5C99B0C
File Size: 855.82 KB, 855816 bytes
MD5: caa7878f9f916c0858d276c7f6222df7
SHA1: 43fca33f6d58f8bf9bccbba4e447e7d0a3f5cd75
SHA256: 2AD472B077DF26F5FC8B1F0C75BC982DEC735C5C7AE908B758AB47FAB0363768
File Size: 855.82 KB, 855816 bytes
MD5: 09ce7653fd496c23a1791ee1ca8377af
SHA1: 23057d2fd2e921e28c0b68e5373ea75e73324664
SHA256: DC2EAE8F4AD756C881DAE7EC9FD90CFB4525F3C949BA3BDE9B47647ED69342C7
File Size: 855.82 KB, 855824 bytes
MD5: 544ccfa16ce48ece1ebbc239faa4641e
SHA1: 609de55e6d8e9cdfe888bb522027008662101857
SHA256: 1562D7A39D9A8AF236D2490EF4C7468FB2BC302375F86D57A5CDCD3BA40B11FD
File Size: 855.82 KB, 855824 bytes
MD5: 90fd92f259b3409a07d3a662edc73b71
SHA1: ccfbdbc89c4ca7382788928c5cc6e79a5227ade4
SHA256: 14524BB43604F015BEFC4077E81D10448AE834929AAE733EE13B58E6A3C4E2C9
File Size: 855.82 KB, 855816 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name TODO: <Company name>
File Description TODO: <File description>
File Version 2, 1, 0, 21-d-5e94740
Internal Name TSLogSDK.dll
Legal Copyright Copyright (C) 2020
Original Filename TSLogSDK.dll
Product Name TSLogSDK
Product Version 2, 1, 0, 21-d-5e94740

Digital Signatures

Signer Root Status
Tenorshare Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Tenorshare Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Tenorshare Co., Ltd. DigiCert Trusted Root G4 Root Not Trusted
Tenorshare Co., Ltd. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • Default Version Info
  • dll
  • x64

Block Information

Total Blocks: 2,827
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2,824
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.DB
  • Rugmi.DBA
  • Rugmi.NO

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...