Trojan

Trojan.Apost removal instruction

Malware Removal

The Trojan.Apost is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Apost virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.Apost?


File Info:

name: 7AE8983DA4614C97CDD1.mlw
path: /opt/CAPEv2/storage/binaries/dd62d43d9fba0fb1b15621053cf1787bc4c054220487c822554668d276a13771
crc32: 0C8F65AD
md5: 7ae8983da4614c97cdd138e6496318c7
sha1: 69fb4434cb6d79baf1c6ae455007898c2324bb0c
sha256: dd62d43d9fba0fb1b15621053cf1787bc4c054220487c822554668d276a13771
sha512: 42423484bd057b29b172fbf10cf0b2c9508c67253f6a648cf6044c207f15c4db7b0641f0e4c7618509685d97557d9cbdf48311050a976b957ac03e217315dc88
ssdeep: 3072:8IVMOCkQgiK0rZXyqvcTuGz2ZElRSjjwZNACu4C8o8dT2VR6rjgdNY:8o1QgrIy+Gz2ZHS2VAg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5247D1232E1C4F7DAA752304EF1AF79B6F6F9614F32994763D00B1E1E316D28626722
sha3_384: 36253b8d3812ec550ba03251909d1da61ec05f7fc2410f2687382eb4fbdd50312be3ee4383453e1699e5f04937bd32f4
ep_bytes: 558bec6aff68004842006860c9400064
timestamp: 2022-07-28 09:58:00

Version Info:

Comments:
CompanyName:
FileDescription: Google Chrome
FileVersion: 1, 2, 0, 1
InternalName: Google Chrome
LegalCopyright: Copyright (C) 2022
LegalTrademarks:
OriginalFilename: Google Chrome
PrivateBuild:
ProductName: Google Chrome
ProductVersion: 1, 2, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan.Apost also known as:

LionicTrojan.Win32.APosT.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.62324641
FireEyeTrojan.GenericKD.62324641
CAT-QuickHealTrojan.Apost
ALYacTrojan.GenericKD.62324641
CylanceUnsafe
ZillyaTrojan.APosT.Win32.2304
SangforTrojan.Win32.Apost.Vtwi
AlibabaTrojan:Win32/APosT.dc2e7a9b
CyrenW32/ABTrojan.VEIA-9187
SymantecTrojan.Gen.MBT
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.APosT.gen
BitDefenderTrojan.GenericKD.62324641
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.62324641
VIPRETrojan.GenericKD.62324641
TrendMicroTROJ_GEN.R002C0PIS22
McAfee-GW-EditionRDN/Generic.dx
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.62324641 (B)
GDataTrojan.GenericKD.62324641
AviraTR/Redcap.osrwx
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.4B1C
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.Z.Agent.217088.RIB
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeRDN/Generic.dx
TrendMicro-HouseCallTROJ_GEN.R002C0PIS22
RisingTrojan.APosT!8.E271 (CLOUD)
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/Chgt.AD

How to remove Trojan.Apost?

Trojan.Apost removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment