Threat Database Trojans Trojan.Rugmi.LDC

Trojan.Rugmi.LDC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,136
Threat Level: 80 % (High)
Infected Computers: 8
First Seen: October 8, 2025
Last Seen: June 23, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.LDC on your system indicates a potential security threat. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.Rugmi.LDC?

Trojan.Rugmi.LDC is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. The name "Trojan" refers to the malicious program's ability to disguise itself as a legitimate application, allowing it to evade detection and gain access to your system. The ".Rugmi.LDC" part of the name is likely a unique identifier assigned by the security software that detected the threat.

How Trojan.Rugmi.LDC Operates

Trojans like Trojan.Rugmi.LDC typically operate by exploiting vulnerabilities in your system or tricking you into installing them. Once inside, they can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your system. Trojans can also be used to launch attacks on other computers, spread spam, or engage in other types of malicious behavior.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.LDC infection can vary, but common indicators include slow system performance, unexpected crashes, and unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive suspicious pop-ups and alerts. In some cases, Trojans can operate silently, making it difficult to detect their presence without the aid of security software.

  • Unexplained changes to your system settings or configuration
  • Appearance of unfamiliar programs or files
  • Increased network activity or data usage
  • System crashes or instability
  • Pop-ups, alerts, or other unusual messages

How to Remove Trojan.Rugmi.LDC

  1. Boot your system in Safe Mode with Networking to prevent the Trojan from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the Trojan.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the Trojan has been completely removed.

Conclusion

Removing Trojan.Rugmi.LDC from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and using reputable security software, you can help protect your system and prevent future infections. Remember to always be cautious when downloading and installing software, and to keep your operating system and security tools up to date to prevent exploitation by malicious programs like Trojan.Rugmi.LDC.

Analysis Report

General information

Family Name: Trojan.Rugmi.LDC
Signature status: Hash Mismatch

Known Samples

MD5: b3555e7fe065645329ea42cfea1ca14d
SHA1: 76d821babebbd1cd6e44ecbf61880406f4dade1f
SHA256: DA1923422F7A7180FF9CC28AE632F3A16051CE625EC919B8F45FCB07F92FE7A8
File Size: 350.50 KB, 350504 bytes
MD5: 671913a19d4938b77826cec2df7f569e
SHA1: 043211790dc5c29b0722c08e88195e0be53f9944
SHA256: 36A4570FF683F7C2E1F157A99B38623B3C3FF3E4A92EBCF68D39A38044059DEB
File Size: 6.44 MB, 6441840 bytes
MD5: 6d36e35302b8add408f8cd6b884b3d25
SHA1: 43a25f9de9737d791f62e6e8cc430948afa6b504
SHA256: 38C2CDDD0416B6DB3D0F8DC54B4E9FFD960AA8B7F449B89435FF37776386C45F
File Size: 691.56 KB, 691560 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Bluestack System Inc.
  • Microsoft Corporation
File Description
  • .NET Host Resolver - 8.0.10
  • Logging Platform
  • VirtualBox Runtime
File Version
  • 25.194.1005.0003
  • 8,0,1024,46610 @Commit: 81cabf2857a01351e5ab578947c7403a5b128ad1
  • 6.1.36.156792
Internal Name
  • .NET Host Resolver - 8.0.10
  • LoggingPlatform.dll
  • VBoxRT
Legal Copyright
  • Copyright (C) 2015-2025 Bluestacks Systems.
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • .NET Host Resolver - 8.0.10
  • BstkRT.dll BstkRT.dll BstkRT.dll
  • LoggingPlatform.dll
Private Build Private build by BuildAdmin
Product Name
  • .NET
  • Bluestack Hypervisor
  • Microsoft OneDrive
Product Version
  • 25.194.1005.0003
  • 8.0.10 @Commit: 81cabf2857a01351e5ab578947c7403a5b128ad1
  • 6.1.36.156792
Special Build b/build/c53fdb6a-d2ae-ac9c-ab5b-b7f457864f8d

Digital Signatures

Signer Root Status
Now.gg, INC DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
.NET Microsoft Code Signing PCA 2011 Hash Mismatch
Microsoft Corporation Microsoft Windows Code Signing PCA 2024 Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 2,114
Potentially Malicious Blocks: 12
Whitelisted Blocks: 1,797
Unknown Blocks: 305

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? x x x ? ? ? ? ? ? x ? ? ? ? ? ? x ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? x 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 ? x 0 ? 0 x ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 x ? 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.LDC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...