Threat Database Trojans Trojan.Rugmi.LF

Trojan.Rugmi.LF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 32
Threat Level: 80 % (High)
Infected Computers: 21,999
First Seen: October 25, 2025
Last Seen: July 21, 2026
OS(es) Affected: Windows

The detection of Trojan.Rugmi.LF on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, steal sensitive information, and disrupt your online activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Rugmi.LF?

Trojan.Rugmi.LF is a type of Trojan horse malware that can infiltrate your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once inside, it can establish a backdoor connection with its command and control server, allowing remote attackers to access your system, steal data, and install additional malware. The name Trojan.Rugmi.LF suggests that it is a unique variant of Trojan horse malware, but its exact characteristics and behavior may vary.

How Trojan.Rugmi.LF Operates

Trojan.Rugmi.LF operates by exploiting weaknesses in your system's security, such as outdated software, weak passwords, or unpatched vulnerabilities. It can also use social engineering tactics to trick you into installing it or providing sensitive information. Once installed, it can run in the background, hiding from detection and waiting for commands from its remote operators. The malware can also spread through infected files, emails, or infected websites, making it essential to be cautious when interacting with online content.

Symptoms of Infection

The symptoms of a Trojan.Rugmi.LF infection can vary, but common signs include slow system performance, unexpected crashes, and unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive suspicious emails or pop-ups. In some cases, the malware can also disable security software or block access to certain websites, making it difficult to detect and remove.

  • Unexplained changes to system settings or files
  • Increased CPU usage or memory consumption
  • Unusual network activity or data transfers
  • Appearance of unfamiliar programs or icons
  • Difficulty accessing certain websites or online services

How to Remove Trojan.Rugmi.LF

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or components.
  3. Uninstall any suspicious programs or applications that may be related to the Trojan.Rugmi.LF infection.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Rugmi.LF from your system requires a combination of technical expertise and caution. By following the steps outlined above and taking proactive measures to secure your system, you can reduce the risk of re-infection and protect your sensitive information. It is essential to stay vigilant and keep your security software up-to-date to detect and prevent future malware threats. Remember to always be cautious when interacting with online content and to never provide sensitive information to untrusted sources.

Analysis Report

General information

Family Name: Trojan.Rugmi.LF
Signature status: No Signature

Known Samples

MD5: 2a95ad72c92a85ace654e6fdf920880f
SHA1: 48d276c23fb7f8ff71e20bae58156eb6c349e71d
SHA256: 38A87D275385DDBF0149ED3A1FD777F190E77B90C2415C1CFD1CB7DFA0A2463C
File Size: 3.16 MB, 3160442 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Oleg N. Scherbakov
File Description 7z Setup SFX (x86)
File Version 1.4.0.1795
Internal Name 7ZSfxMod
Legal Copyright Copyright © 2005-2010 Oleg N. Scherbakov
Original Filename 7ZSfxMod_x86.exe
Private Build June 27, 2010
Product Name 7-Zip SFX
Product Version 1.4.0.1795

File Traits

  • 7-zip Installer
  • 7zSFX
  • Installer Manifest
  • Installer Version
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dik.ymo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dik.ymo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\hashrate-supervisor16.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\hashrate-supervisor16.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\iert.dwhp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\iert.dwhp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\msvcr100.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\msvcr100.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\python34.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\python34.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\videouploader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\videouploader.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx

Shell Command Execution

(NULL) C:\Users\Voacnlkl\AppData\Local\Temp\Hashrate-Supervisor16.exe

Trending

Most Viewed

Loading...