Threat Database Trojans Trojan.Tuscas.AA

Trojan.Tuscas.AA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,044
Threat Level: 80 % (High)
Infected Computers: 633
First Seen: June 29, 2019
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Tuscas.AA on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Tuscas.AA?

Trojan.Tuscas.AA is a type of malware that can compromise the security and integrity of your computer system. The term "Trojan" refers to a broad category of malicious software that disguises itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to a system. The specific designation ".Tuscas.AA" suggests a unique identifier or variant within the Trojan category, but without more detailed information, it's essential to focus on general principles of malware removal and system security.

How Trojan.Tuscas.AA Operates

Malware like Trojan.Tuscas.AA typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can perform a variety of malicious actions, including but not limited to, stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. The exact operations of Trojan.Tuscas.AA can vary, but the goal is often to compromise system security for financial gain or to disrupt operations.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may include slow system performance, frequent crashes, or unexpected behavior from applications. You might also notice unfamiliar programs or toolbars in your browser, or receive alerts from your security software indicating malicious activity. Sometimes, infections can be asymptomatic, making regular system checks and security scans crucial for early detection.

How to Remove Trojan.Tuscas.AA

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in. The process to boot into Safe Mode can vary depending on your operating system version.
  2. Perform a Full Scan with a Reputable Tool: Utilize a well-regarded anti-malware tool, such as SpyHunter, to scan your system thoroughly. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, or Edge to their default settings can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot and Re-scan: After taking these steps, reboot your system and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Tuscas.AA and securing your system requires a combination of the right tools and cautious behavior. By understanding how Trojans operate and following the steps outlined above, you can significantly reduce the risk of infection and protect your personal data. Regularly updating your operating system, applications, and security software, along with being vigilant when clicking on links or installing software, are key practices in maintaining system security. If you're unsure about any part of the removal process, consider consulting with a professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.Tuscas.AA
Signature status: No Signature

Known Samples

MD5: e130b19f6165f4db27869370d987e834
SHA1: ef65c4996ace2911a678ae59acc3ff4680a89956
SHA256: 019E032D9AF864AE8AD476A13B390172B74FDCD9DE49656465D0F41CE5C34F0E
File Size: 250.37 KB, 250368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 13
Potentially Malicious Blocks: 9
Whitelisted Blocks: 4
Unknown Blocks: 0

Visual Map

x 0 0 x x 0 0 x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Tuscas.AA
  • Tuscas.AB

Files Modified

File Attributes
c:\users\user\appdata\local\temp\~aa53.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\cmdlwwiz\rrinubst.exe Generic Write,Read Attributes
c:\windows\syswow64\spattray.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::mobsdown C:\Users\Hucqbzlq\AppData\Roaming\cmdlwwiz\rrinubst.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\startupapproved\run::mobsdown RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Service Control
  • OpenSCManager
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
Show More
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Hucqbzlq\AppData\Roaming\cmdlwwiz\rrinubst.exe "C:\Users\Hucqbzlq\AppData\Roaming\cmdlwwiz"
C:\Users\Hucqbzlq\AppData\Local\Temp\~AA53.tmp 2536 250376 1064 1

Trending

Most Viewed

Loading...