Threat Database Trojans Trojan.Slugin.B

Trojan.Slugin.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,054
Threat Level: 80 % (High)
Infected Computers: 287
First Seen: July 12, 2021
Last Seen: July 22, 2026
OS(es) Affected: Windows

The detection of Trojan.Slugin.B on your system indicates a potential security threat that requires immediate attention. Trojan horses, like Trojan.Slugin.B, are malicious programs that can compromise the security and integrity of your computer. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Slugin.B?

Trojan.Slugin.B is a type of malware that disguises itself as a legitimate program to gain unauthorized access to your computer. Once inside, it can cause significant damage, including data theft, system crashes, and the installation of additional malware. The name Trojan.Slugin.B suggests that it is a Trojan-type threat, but its specific characteristics and behavior may vary. It is crucial to approach this threat with caution and follow a systematic removal process to ensure your system's safety.

How Trojan.Slugin.B Operates

Trojan.Slugin.B, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as opening malicious email attachments, downloading infected software, or visiting compromised websites. Once installed, the Trojan can create backdoors for remote access, allowing attackers to control your computer, steal sensitive information, or use your system for malicious activities. The exact mechanisms of Trojan.Slugin.B might not be fully understood without specific analysis, but its potential for harm is clear.

Symptoms of Infection

The symptoms of a Trojan.Slugin.B infection can vary, but common signs include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You might also notice unfamiliar programs or toolbars in your browser, changes in your homepage, or an increase in spam emails. Sometimes, the infection may not exhibit noticeable symptoms, making it difficult to detect without proper scanning tools. If you suspect that your system is infected, it is vital to act quickly to minimize potential damage.

How to Remove Trojan.Slugin.B

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to give you a cleaner environment for removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove Trojan.Slugin.B and any associated malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time you noticed the infection. Be cautious and only remove programs you are sure are safe to uninstall.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Slugin.B requires careful and systematic steps to ensure that your system is thoroughly cleaned and protected. It is also crucial to adopt preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening emails or downloading files from the internet. By understanding the nature of Trojan horses and taking proactive steps, you can significantly reduce the risk of future infections and maintain the security and integrity of your computer.

Analysis Report

General information

Family Name: Trojan.Slugin.B
Signature status: No Signature

Known Samples

MD5: 5b0ee1b06f1a90b3156ea7c1a5b9920e
SHA1: 8015e2839c5c0c0329e92893627d664a43061426
SHA256: C1877A055E3FA8A69EFDF482EEA0C1F9593678F17930155F7585C62BAFEC9506
File Size: 483.81 KB, 483811 bytes
MD5: 98b99a210a6e6a886050b759eec3506d
SHA1: a66f8e71f682bbed94ae629408eb3b7726cfaf37
SHA256: D2EEE0713FC55D3B110582B4A68369300EBD2A59B473E7EE50AC6FF65D6968E7
File Size: 1.03 MB, 1031139 bytes
MD5: eb4acbaedd365a94ac01d44934bdebde
SHA1: 4bfce9a75cdf5a2ebb88b80c72468aaca8c814c9
SHA256: 6135A5ABE346A3AF1757998C92AFF58732468333B6C4A12714DB761703E3454B
File Size: 198.14 KB, 198144 bytes
MD5: 414731c8de91b6e921284dea4cf673ba
SHA1: 171c4b9b8d00ed8159054f34be6531fff23d3e0a
SHA256: 6788E3D15D5F5432C9F6B8FFCE17AC581A90F408F910913609D2C28725E9E0E5
File Size: 199.03 KB, 199031 bytes
MD5: 8375e7197646f957200d4689661da934
SHA1: acb11bc9eb8a6127b146573e43977f85450c3b00
SHA256: 51A98D051B16B7026DC517282BF34FC015BD5D2F7A36749CBE8B5D592D3314D9
File Size: 848.36 KB, 848355 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Infogrames
  • MySQL AB
File Description
  • Administrator Tool for Win32
  • GP4_Install_Startup MFC Application
File Version
  • 1.0.0.0
  • 1, 0, 0, 1
Internal Name
  • GP4_Install_Startup
  • WinMySQLadmin
Legal Copyright
  • Copyright (C) 1999
  • Read Public File
Original Filename GP4_Install_Startup.EXE
Product Name
  • GP4_Install_Startup Application
  • WinMySQLadmin
Product Version
  • 1.0.0.0
  • 1, 0, 0, 1

File Traits

  • 2+ executable sections
  • big overlay
  • BINinO
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • MZ (In Overlay)
  • nosig nsis
  • No Version Info
  • SusSec
Show More
  • x86

Block Information

Total Blocks: 513
Potentially Malicious Blocks: 0
Whitelisted Blocks: 507
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\roaming\wplugin.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\wplugin.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKCU\software\user914\1214104697::1919251317 + RegNtPreCreateKey
HKCU\software\user914\1214104697::-456464662 RegNtPreCreateKey
HKCU\software\user914\1214104697::1462786655 RegNtPreCreateKey
HKCU\software\user914\1214104697::-912929324 # RegNtPreCreateKey
HKCU\software\user914\1214104697::1006321993 ½ RegNtPreCreateKey
HKCU\software\user914\1214104697::-1369393986 http://lpbmx.ru/logos.gifhttp://macedonia.my1.ru/mainh.gifht RegNtPreCreateKey
HKCU\software\user914\1214104697::549857331 �g;�_��6̚��6�zu)����#�]��^t��A�P�Av�h�m,�:,޸%O4��[�� RegNtPreCreateKey
Show More
HKCU\software\user914::u1_0 ⠺첖 RegNtPreCreateKey
HKCU\software\user914::u2_0 RegNtPreCreateKey
HKCU\software\user914::u3_0 晁ă RegNtPreCreateKey
HKCU\software\user914::u4_0 RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation