Threat Database Trojans Trojan.Rugmi.FL

Trojan.Rugmi.FL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,113
Threat Level: 80 % (High)
Infected Computers: 14
First Seen: March 14, 2026
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.FL on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Rugmi.FL?

Trojan.Rugmi.FL is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs or files to gain unauthorized access to a computer system. Once inside, it can perform a variety of harmful actions, including data theft, system compromise, and the installation of additional malware. The name "Trojan.Rugmi.FL" is a detection label used by security software to identify this specific threat, but it does not necessarily indicate a specific malware family or origin.

How Trojan.Rugmi.FL Operates

Trojan.Rugmi.FL, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as downloading and running malicious files, clicking on infected links, or opening attachments from unsolicited emails. Once installed, the malware can communicate with its command and control servers to receive instructions, which may include stealing sensitive information, downloading additional malware, or using the infected computer as part of a botnet for malicious activities.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.FL infection can vary, but common indicators include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. You might also notice suspicious network activity, unexpected changes to system settings, or the presence of unfamiliar files and folders. In some cases, the infection may not exhibit noticeable symptoms, making it difficult to detect without the use of antivirus software.

How to Remove Trojan.Rugmi.FL

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the Trojan.Rugmi.FL malware.
  3. Uninstall any suspicious programs or applications that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Rugmi.FL from your system requires a thorough and careful approach to ensure that all components of the malware are eliminated. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can help protect your computer from future malware infections. Remember, prevention and vigilance are key to securing your digital environment.

Analysis Report

General information

Family Name: Trojan.Rugmi.FL
Signature status: Hash Mismatch

Known Samples

MD5: a9746c7ff0d6fac0f9e334de61e071df
SHA1: 6ca098e8bd3e6dfd3aadb2369885b6e25af25e81
SHA256: 8C899CB16432D233970EDCA25209387DFDF9E44ED859B54827B9FA500C3A7795
File Size: 4.25 MB, 4249271 bytes
MD5: 82084d9c46419e209aa3a7a174a595d8
SHA1: 6207d92a76e6dd6944c48864a99bab63729e206c
SHA256: 8F3039779840B3FC6164D29EC5BF78EADAAB78A37E963BDBACFECC7CEB2F6FF8
File Size: 266.10 KB, 266096 bytes
MD5: 238449bae6ce98ebfb9bc518459209ef
SHA1: 04c176b9043616a45724d7bb18e4a48b37a60a5c
SHA256: 99D4C8953C8EE41F2DFACE3B1AC43DBDFA40C83765558C38F380E390A03919DE
File Size: 192.62 KB, 192616 bytes
MD5: 8023af84d6c612c806dc6818c01bf063
SHA1: 2a188f98f135a2d0f596a3aa5943bac7ab6c6e3b
SHA256: 167C3D140BAAE765B09F069CA354173B632463313DB4CCE16930102B17411EBE
File Size: 1.50 MB, 1502800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Arabic Stemmer for Translation Services
  • This installation was built with Inno Setup.
Company Name
  • COLTEC M.E.
  • Microsoft(r) Corporation
  • Microsoft Corporation
File Description
  • Arabic Stemmer for MS Office 2009, by COLTEC M.E.
  • DirectX IL for Redistribution
  • Good Setup
  • Microsoft® C/C++ OpenMP Runtime
File Version
  • 101.7.2308.24
  • 14.44.35112.1
  • 14.0.0.3
  • 2.0.0.0
Internal Name
  • DirectX IL for Redistribution
  • msb1star.dll
  • VCOMP140.DLL
Legal Copyright
  • (c) Microsoft Corporation. All rights reserved.
  • Copyright © 2009 COLTEC M.E.
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation.
Original Filename
  • dxil.dll
  • msb1star.DLL
  • VCOMP140.DLL
Product Name
  • Coltec's Arabic Stemmer
  • Good
  • Microsoft® Visual Studio®
Product Version
  • 101.7.2308.24 (release/github-release-1.7.2308, ShaderCompiler.dxcbin.0.231001.0+01e0098ba93c6973e72b7fa37b8ff7f019e383f7-101.7.2308.24.github-release-1.7.2308)
  • 14.44.35112.1
  • 14.0.0.3
  • 9.1

Digital Signatures

Signer Root Status
Coltec Middle East Company for Computer Technologies Class 3 Public Primary Certification Authority Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2010 Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch
Microsoft Windows Software Compatibility Publisher Microsoft Windows Third Party Component CA 2013 Hash Mismatch

File Traits

  • dll
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 4,804
Potentially Malicious Blocks: 16
Whitelisted Blocks: 3,816
Unknown Blocks: 972

Visual Map

0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x x x 0 x ? 0 x x x x x x x 0 x 0 ? ? x 0 x ? 0 x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 1 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 1 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 1 ? ? ? ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 0 ? ? 0 ? 0 0 0 ? ? ? 0 0 ? ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 ? ? 0 ? ? 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 ? 0 0 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? 1 0 0 0 ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 ? 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Downloader.Gen.PP

Files Modified

File Attributes
c:\programdata\drv\adplusmanager.exe.config Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\drv\dbgeng.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\drv\dbghelp.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\drv\driver.cfg Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\drv\late.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\drv\linkeragent56.conf Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\7b17489.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8amdh.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-8amdh.tmp\adplusmanager.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8amdh.tmp\dbgeng.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-8amdh.tmp\dbghelp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8amdh.tmp\driver.cfg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8amdh.tmp\late.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8amdh.tmp\linkeragent56.conf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-if8bl.tmp\6ca098e8bd3e6dfd3aadb2369885b6e25af25e81_0004249271.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\drv\crisp.exe Read Attributes,Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �v(�1�1HO@V�A��N�_�zb"hy�9{b��P�������m�����$წ���&M�=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �v(�1�1HO@V�A��N�_�zb"hy�9{b��P����������m�����$წ���&M�=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v����#��(�*�"1�1HO@V�A��H[u_�zb"hc�wk�q{b��P������������m��gi�V����$�8წ���&MA�=�S)�B1_B��T�Vw��`���%�������AE��"��D��&��$���LA*�" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAreMappedFilesTheSame
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCopyFileChunk
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN

Shell Command Execution

"C:\Users\Mpqmuiau\AppData\Local\Temp\is-IF8BL.tmp\6ca098e8bd3e6dfd3aadb2369885b6e25af25e81_0004249271.tmp" /SL5="$D0322,3861617,121344,c:\users\user\downloads\6ca098e8bd3e6dfd3aadb2369885b6e25af25e81_0004249271"
"C:\Users\Mpqmuiau\AppData\Local\Temp\is-8AMDH.tmp\LatE.exe"

Trending

Most Viewed

Loading...