Category:Trojan,Downloader
[Kaspersky]Trojan.Win32.Zapchast;
[Panda]Adware/Lop,Adware/Apropos,Trj/Downloader.OF,Trj/Nedibed.A
TrojanDownloader.Win32.Apropo Detection :
Files:
[%PROGRAM_FILES%]\closei~1\file glue.dll
[%PROGRAM_FILES%]\closei~1\roam.bin
[%PROGRAM_FILES%]\closei~1\roamlink.bin
[%PROGRAM_FILES%]\closei~1\roamlopen.bin
[%PROGRAM_FILES%]\closei~1\rtorelink.bin
[%PROGRAM_FILES%]\closei~1\storelink.bin
[%PROGRAM_FILES%]\closei~1\storeopen.bin
[%PROGRAM_FILES%]\closei~1\storeroam.bin
[%PROGRAM_FILES%]\closei~1\storropen.bin
[%PROGRAM_FILES%]\enc dart junk\eggs cast.exe
[%PROGRAM_FILES%]\enc dart junk\objfast.exe
[%PROGRAM_FILES%]\enc dart junk\one.exe
[%PROGRAM_FILES%]\saveba~1\clock.exe
[%SYSTEM%]\acctres110v.dll
[%SYSTEM%]\bmamsd.exe
[%SYSTEM%]\chaup_incred_9.exe
[%SYSTEM%]\cmmorier.exe
[%SYSTEM%]\conkui.exe
[%SYSTEM%]\crehe220.exe
[%SYSTEM%]\dco_fmt.exe
[%SYSTEM%]\ddaplus.exe
[%SYSTEM%]\dfracc.exe
[%SYSTEM%]\dgr2disp.exe
[%SYSTEM%]\dgskcopy.exe
[%SYSTEM%]\dissrv.exe
[%SYSTEM%]\dmienum.exe
[%SYSTEM%]\dswsetup.exe
[%SYSTEM%]\encscli.exe
[%SYSTEM%]\finontr.exe
[%SYSTEM%]\fondntld.exe
[%SYSTEM%]\fpltvrfy.exe
[%SYSTEM%]\frashlex.exe
[%SYSTEM%]\hnesrvc.exe
[%SYSTEM%]\hpgs31.exe
[%SYSTEM%]\imagx5715q.dll
[%SYSTEM%]\ir3svc.exe
[%SYSTEM%]\isirch.exe
[%SYSTEM%]\lan70u.exe
[%SYSTEM%]\mlappagn.exe
[%SYSTEM%]\mqaanmgr.exe
[%SYSTEM%]\nlhtml604k.dll
[%SYSTEM%]\pifg13.exe
[%SYSTEM%]\pxter40.exe
[%SYSTEM%]\qprdx32.exe
[%SYSTEM%]\shgmdlg.exe
[%SYSTEM%]\shuoyfrc.exe
[%SYSTEM%]\tpianui.exe
[%SYSTEM%]\wmnptdll.exe
[%SYSTEM%]\wsacript.exe
[%WINDOWS%]\system\dmutil.exe
[%WINDOWS%]\system\dpmimn07.exe
[%WINDOWS%]\system\occp32.exe
[%WINDOWS%]\system\quapol.exe
[%WINDOWS%]\system\vz9pita.exe
[%PROGRAM_FILES%]\closei~1\file glue.dll
[%PROGRAM_FILES%]\closei~1\roam.bin
[%PROGRAM_FILES%]\closei~1\roamlink.bin
[%PROGRAM_FILES%]\closei~1\roamlopen.bin
[%PROGRAM_FILES%]\closei~1\rtorelink.bin
[%PROGRAM_FILES%]\closei~1\storelink.bin
[%PROGRAM_FILES%]\closei~1\storeopen.bin
[%PROGRAM_FILES%]\closei~1\storeroam.bin
[%PROGRAM_FILES%]\closei~1\storropen.bin
[%PROGRAM_FILES%]\enc dart junk\eggs cast.exe
[%PROGRAM_FILES%]\enc dart junk\objfast.exe
[%PROGRAM_FILES%]\enc dart junk\one.exe
[%PROGRAM_FILES%]\saveba~1\clock.exe
[%SYSTEM%]\acctres110v.dll
[%SYSTEM%]\bmamsd.exe
[%SYSTEM%]\chaup_incred_9.exe
[%SYSTEM%]\cmmorier.exe
[%SYSTEM%]\conkui.exe
[%SYSTEM%]\crehe220.exe
[%SYSTEM%]\dco_fmt.exe
[%SYSTEM%]\ddaplus.exe
[%SYSTEM%]\dfracc.exe
[%SYSTEM%]\dgr2disp.exe
[%SYSTEM%]\dgskcopy.exe
[%SYSTEM%]\dissrv.exe
[%SYSTEM%]\dmienum.exe
[%SYSTEM%]\dswsetup.exe
[%SYSTEM%]\encscli.exe
[%SYSTEM%]\finontr.exe
[%SYSTEM%]\fondntld.exe
[%SYSTEM%]\fpltvrfy.exe
[%SYSTEM%]\frashlex.exe
[%SYSTEM%]\hnesrvc.exe
[%SYSTEM%]\hpgs31.exe
[%SYSTEM%]\imagx5715q.dll
[%SYSTEM%]\ir3svc.exe
[%SYSTEM%]\isirch.exe
[%SYSTEM%]\lan70u.exe
[%SYSTEM%]\mlappagn.exe
[%SYSTEM%]\mqaanmgr.exe
[%SYSTEM%]\nlhtml604k.dll
[%SYSTEM%]\pifg13.exe
[%SYSTEM%]\pxter40.exe
[%SYSTEM%]\qprdx32.exe
[%SYSTEM%]\shgmdlg.exe
[%SYSTEM%]\shuoyfrc.exe
[%SYSTEM%]\tpianui.exe
[%SYSTEM%]\wmnptdll.exe
[%SYSTEM%]\wsacript.exe
[%WINDOWS%]\system\dmutil.exe
[%WINDOWS%]\system\dpmimn07.exe
[%WINDOWS%]\system\occp32.exe
[%WINDOWS%]\system\quapol.exe
[%WINDOWS%]\system\vz9pita.exe
Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
Removing TrojanDownloader.Win32.Apropo:
you can run trial version of ExterminateIt, or remove TrojanDownloader.Win32.Apropo manually..ExterminateIt effectively and automatically removes Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware) from you computer.
Download ExterminateIt! to instantly get rid of TrojanDownloader.Win32.Apropo!
Also Be Aware of the Following Threats:
Removing Search123 Adware
Removing TrojanDownloader.Win32.Apropo Trojan
Pigeon.AER Trojan Information
Pigeon.BAJ Trojan Information