Trojan

Trojan:Win32/Aptdrop.RU removal guide

Malware Removal

The Trojan:Win32/Aptdrop.RU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Aptdrop.RU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

www.billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
boatshowradio.com
dna-cp.com

How to determine Trojan:Win32/Aptdrop.RU?


File Info:

crc32: 3532E55C
md5: 0938467927b77d12e74629d05a3c2b7e
name: 0938467927B77D12E74629D05A3C2B7E.mlw
sha1: 036328306fa9f86ceae51ac4063a1d02d58d6ed3
sha256: 3ccdaa356484c1838cc89654fbcf58c08d05518da6485146facf2ac92abfb39c
sha512: 3b82921cb43d5b14c31a3a761c2fed4d39f06f90d82b5832a395851f17b7d3bbf752b949fdb2fd1a63d41353c43582cf0e18d926258f8c45a5a62697f234f3c4
ssdeep: 3072:/ft6S5vxb9Lq2R12D03PsXETKlg79zYlRm34eqQfomkb5:/ft6uNU2eDZETKO9zeRm3qQfop
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WUDFHost.exe
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17134.1
FileDescription: Windows Driver Foundation - User-mode Driver Framework Host Process
OriginalFilename: WUDFHost.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Aptdrop.RU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d0e41 )
LionicTrojan.Win32.GandCrypt.4!c
DrWebBackDoor.Tofsee.192
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.765
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/GandCrypt.ff7762b6
K7GWTrojan ( 0053d0e41 )
Cybereasonmalicious.927b77
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.GLAJ
APEXMalicious
AvastWin32:ReposFxg-F [Trj]
KasperskyTrojan-Ransom.Win32.GandCrypt.fhu
BitDefenderTrojan.Mint.Zamg.Q
NANO-AntivirusTrojan.Win32.GandCrypt.fiffwy
MicroWorld-eScanTrojan.Mint.Zamg.Q
TencentWin32.Trojan.Gandcrypt.Eom
Ad-AwareTrojan.Mint.Zamg.Q
SophosMal/Generic-R + Mal/Elenoocka-G
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34050.oq0@aSYIB7j
TrendMicroTrojan.Win32.ELENOOKA.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Worm.dh
FireEyeGeneric.mg.0938467927b77d12
EmsisoftTrojan.Mint.Zamg.Q (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1124789
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.2817DCE
MicrosoftTrojan:Win32/Aptdrop.RU
ArcabitTrojan.Mint.Zamg.Q
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.fhu
GDataTrojan.Mint.Zamg.Q
TACHYONRansom/W32.GandCrab.229888.B
AhnLab-V3Malware/Win.Tofsee.R374616
Acronissuspicious
McAfeePacked-FMJ!0938467927B7
VBA32BScope.Trojan.Packed
MalwarebytesTrojan.Bunitu
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.ELENOOKA.SM.hp
RisingTrojan.Generic@ML.100 (RDML:DY34+bngpc7xfOJum4CPQA)
IkarusTrojan-Banker.GootKit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLAY!tr.ransom
AVGWin32:ReposFxg-F [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HxMBtwMA

How to remove Trojan:Win32/Aptdrop.RU?

Trojan:Win32/Aptdrop.RU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment