Trojan

Win32/TrojanDownloader.Rugmi.EZM (file analysis)

Malware Removal

The Win32/TrojanDownloader.Rugmi.EZM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Rugmi.EZM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)

How to determine Win32/TrojanDownloader.Rugmi.EZM?


File Info:

name: B90BBDE42F4BDE5CD6AF.mlw
path: /opt/CAPEv2/storage/binaries/6ca96dc42c00a719824aaeef475650100a7ed733fee9776242ed68cb42ed6183
crc32: BFC5D2B2
md5: b90bbde42f4bde5cd6afd9bed32081bd
sha1: f393b938ebd0d2c81d21881853b0e49497277d8c
sha256: 6ca96dc42c00a719824aaeef475650100a7ed733fee9776242ed68cb42ed6183
sha512: 27b494c642089921f2492565377b4802c8199226b9fb425bf2a4c053540e217f5b1ded7d9b2f19162d1b2ccf65129000ff60878df70c6ed54acb54b87786f207
ssdeep: 24576:lTfEsP85DgJrivY05+Qa+W3+1V51SAYjiv2wGPoyI1Jv2Gtigd0WG9BD:ZcsQ6Qh1VjVYjiOwGt62Jgd0WGv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F985D067B294753EC46937361573B02465FBAA6DF8177E2677E0C48CCF220C01E7AA26
sha3_384: 95b926e3f64e792da63e27573c8879d49a51faf2d2de37929a57c8a30597a0853cfbf55fd806247e58f21f7437f2b900
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-10-12 11:15:57

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: atikmdag-patcher Setup
FileVersion:
LegalCopyright: MonitorRes
OriginalFileName:
ProductName: atikmdag-patcher
ProductVersion: 1.4.7
Translation: 0x0000 0x04b0

Win32/TrojanDownloader.Rugmi.EZM also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Pincav.4!c
McAfeeArtemis!B90BBDE42F4B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 0058b8581 )
BitDefenderTrojan.GenericKD.43000415
K7GWTrojan-Downloader ( 0058b8581 )
ArcabitTrojan.Generic.D290225F
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Rugmi.EZM
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
AlibabaTrojanDownloader:Win32/Pincav.5b6db7e6
NANO-AntivirusTrojan.Win32.Pincav.hcbezm
MicroWorld-eScanTrojan.GenericKD.43000415
DrWebBackDoor.Wirenet.557
McAfee-GW-EditionBehavesLike.Win32.DLAssistant.tc
FireEyeTrojan.GenericKD.43000415
EmsisoftTrojan.GenericKD.43000415 (B)
AviraTR/AD.NsisInject.ajxlj
GDataTrojan.GenericKD.43000415
MAXmalware (ai score=86)
TencentWin32.Trojan.Pincav.Pdvv
IkarusTrojan-Downloader.Win32.Rugmi
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Pincav.BRAAJ!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.42f4bd
AvastWin32:Trojan-gen

How to remove Win32/TrojanDownloader.Rugmi.EZM?

Win32/TrojanDownloader.Rugmi.EZM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment