Trojan.Rugmi.TC
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 15,100 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 45 |
| First Seen: | August 19, 2025 |
| Last Seen: | June 28, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Rugmi.TC on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating characteristics, symptoms of infection, and a step-by-step guide on how to remove it from your system.
Table of Contents
What Is Trojan.Rugmi.TC?
Trojan.Rugmi.TC is a type of malicious software, commonly referred to as a Trojan, that can compromise the security and integrity of your computer system. The term "Trojan" originates from the legendary Trojan Horse, symbolizing a malicious entity that disguises itself as something benign to gain unauthorized access. Unlike viruses, Trojans do not replicate but can cause significant harm by allowing unauthorized access to your system, stealing sensitive information, or disrupting system operations.
How Trojan.Rugmi.TC Operates
Trojan.Rugmi.TC, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, including opening malicious email attachments, downloading infected software, or visiting compromised websites. Once installed, it can create a backdoor on your system, allowing remote access and control by the attacker. This can lead to a range of malicious activities, from data theft and espionage to the use of your system as a botnet for further malicious activities.
Symptoms of Infection
Identifying a Trojan infection can be challenging due to its stealthy nature. However, there are several symptoms that may indicate the presence of Trojan.Rugmi.TC or similar malware on your system. These include but are not limited to, unexpected system crashes, slow system performance, unusual network activity, appearance of unwanted or suspicious programs, and unauthorized changes to system settings or files. If you observe any of these symptoms, it is crucial to take immediate action to secure your system.
How to Remove Trojan.Rugmi.TC
- Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
- Conduct a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.Rugmi.TC and any associated malware.
- Manually uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
- Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings that the Trojan may have installed.
- After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.
Conclusion
The removal of Trojan.Rugmi.TC requires careful and systematic steps to ensure that all components of the malware are eliminated from your system. It is also essential to adopt preventive measures to avoid future infections, including keeping your operating system and software up-to-date, using strong and unique passwords, being cautious with email attachments and downloads, and regularly scanning your system for malware. By taking these steps, you can significantly enhance the security of your system and protect your personal data from potential threats.
Analysis Report
General information
| Family Name: | Trojan.Rugmi.TC |
|---|---|
| Signature status: | Hash Mismatch |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
954f4793db6fe15ede254fec7014f8df
SHA1:
1eb239bdc322741c7b919997cdac525d2a43b271
SHA256:
6303338D410EB13056A6667BB03F1ED394BB8C9DEFB8315AA87AA2DB4E01A9F1
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
314b55862607a331653dfae8f817f1ca
SHA1:
15cd2531eb2f676fc1981110329acfe8a4fe00bd
SHA256:
29C14B5FBE6339460F940912454C0D479F728755E4868D41D1BE48E6995BAB61
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
26bdbeeafbcb5403edae38d80fa508eb
SHA1:
5f1dcd19bff7cefdf192f394fc879dfb361660eb
SHA256:
82B19747645326479E2068FE08D850E1696E021F39FDF1A71874FE91B71FBEE5
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
9388982b2a064097236c0d0851c77235
SHA1:
5f1b9e194839a04d2594c934e21ebf45ba218dca
SHA256:
F1DEE451443FE9EBC84EE235AA3BCFFAD8185A4B50B1DC207D89776E47B85750
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
d97f2d035c72b7f5ba99e7539e657b59
SHA1:
fe7cd0ee300ac1ed0e5bfc0db84a01172de5500c
SHA256:
3DF544D0299B5705406661055322D3739F9CBC15DE832063A5E8C596D108E172
File Size:
4.67 MB, 4669768 bytes
|
Show More
|
MD5:
66e2e3e624f19af5ef0687b5a8f6492f
SHA1:
1affe5ba808bf4490af092111e81eac5c4f00d8a
SHA256:
5C32BCB36ECED6E173C5FAC4FCFA539F36C18216814039FB8A757D229CB386E7
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
095d82ae53b94a2efd7c8504bff674fb
SHA1:
133649ef3e29f8eaa5929c90fb6f6d418f8b9063
SHA256:
75009E7D0972E3B3DF2AF15AE1A5729E6E33BD5BB37F7D220AFBEA3F02DE70E3
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
ef169bf23fe8b0867d157f32c4b86107
SHA1:
5d34b5f8c4567da2dcddf8638cc8cd2eb5853ceb
SHA256:
06ACA5088BC64598D028E5689B7ACB730B19C318DEB71E210C1E7D93216C34E4
File Size:
4.67 MB, 4669768 bytes
|
|
MD5:
f45c19bbbb90ead94910b4db21556bb2
SHA1:
8425683bef9747c7a452281a2550a24615cd7ed9
SHA256:
A1A40FD20E981B65474D617B492A576316B6A950978DFD33A224D20B5B804180
File Size:
4.67 MB, 4669768 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Comodo Security Solutions Inc | Sectigo Public Code Signing Root R46 | Hash Mismatch |
File Traits
- 2+ executable sections
- dll
- HighEntropy
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 6,820 |
|---|---|
| Potentially Malicious Blocks: | 1,133 |
| Whitelisted Blocks: | 5,686 |
| Unknown Blocks: | 1 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Expiro.GA
- Rugmi.TB
- Rugmi.TC
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
79 additional items are not displayed above. |