Trojan

What is “Trojan:Win32/AproposMedia”?

Malware Removal

The Trojan:Win32/AproposMedia is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AproposMedia virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/AproposMedia?


File Info:

name: FA8FC098881A9372C4F1.mlw
path: /opt/CAPEv2/storage/binaries/e3f7dc1f133bbb2df2bd1a51d2a5261eb1078067e6d20a3d897c3a3174e5c352
crc32: 41033627
md5: fa8fc098881a9372c4f13559ac4def53
sha1: 5edd961571ded59dffa108c776af4be7cb026785
sha256: e3f7dc1f133bbb2df2bd1a51d2a5261eb1078067e6d20a3d897c3a3174e5c352
sha512: 746f1b608efe32c5818af8c307cc50b74ce81f9ca3cbaa95829482be347c056fb8c853f9211ad0dc06674e86a4bda2b1f029d95f5aee254a625770f8d3248912
ssdeep: 6144:cksqyAt78/8mMEUseRNcMXmKiaZGSODizdjN/X:5LyADmuNNXmhkvJZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197A41270135A12ECFB1CE9B3D2876E70075A49699E416FD3470E11A9C876CADEF181C3
sha3_384: 005bc73a7ddeeb14bf6b034a87f1300da2af8d0a60ee4db3ddb5eefab29be3e6bd118a2125f80bf9b0eee24c00d19798
ep_bytes: e99b48fdff2155105b844be5cfb0c1f8
timestamp: 2005-10-13 06:34:40

Version Info:

0: [No Data]

Trojan:Win32/AproposMedia also known as:

LionicHacktool.Win32.NSAnti.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.435219
FireEyeGeneric.mg.fa8fc098881a9372
SkyhighBehavesLike.Win32.VBObfus.gt
ALYacGen:Variant.Zusy.435219
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005728071 )
AlibabaVirTool:Win32/NSAnti.b957d030
K7GWTrojan ( 005728071 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Zusy.D6A413
BitDefenderThetaAI:Packer.A134EC701E
SymantecSpyware.Apropos
ESET-NOD32a variant of Win32/Kryptik.RJA
APEXMalicious
KasperskyPacked.Win32.NSAnti.r
BitDefenderGen:Variant.Zusy.435219
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Xpirat [Inf]
TACHYONTrojan/W32.Packer.471040.Z
SophosMal/Packer
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebAdware.Apropos
VIPREGen:Variant.Zusy.435219
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Zusy.435219 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Heuristic-162!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.a
XcitiumMalware@#2w4rgjmt97u8g
MicrosoftTrojan:Win32/AproposMedia
ZoneAlarmPacked.Win32.NSAnti.r
GDataGen:Variant.Zusy.435219
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Crypt.R22127
MAXmalware (ai score=96)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/Genetic.gen
RisingRootkit.Agent!8.F5 (TFE:1:aUPGo40M6RU)
YandexTrojan.AproposMedia!eTRc+8HQa4U
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.15057.susgen
FortinetW32/Crypt.T!tr
AVGWin32:Xpirat [Inf]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/AproposMedia?

Trojan:Win32/AproposMedia removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment