Home Malware Programs Adware ApptoU

ApptoU

Posted: April 2, 2014

Threat Metric

Ranking: 12,372
Threat Level: 2/10
Infected PCs: 4,829
First Seen: April 2, 2014
Last Seen: September 11, 2023
OS(es) Affected: Windows


ApptoU Screenshot 1ApptoU is a Potentially Unwanted Program that changes your search results by adding extra advertisements and sponsored results. Adware like ApptoU often is problematic by providing advertising content that isn't guaranteed to be safe, and, in any case, may harm your browser's performance without giving you any advantages in return. Malware researchers recommend appropriate PC security tools for removing ApptoU or for detecting its installation sources, which use PUP-installing software that also may install other types of unwanted browser add-ons.

Why ApptoU Equals 'Advertisements to You' Even if You'd Like to Opt Out

Browser add-ons that think they know what is best for your search results are extremely common, but show no signs of slacking in quantity for the foreseeable future, with new ones like ApptoU appearing on the landscape regularly. Notably, ApptoU is a retreading of old territory in more ways than one, and uses the same Installerex installation utility that malware experts have seen used for other PUPs, such as DiscountLocator or the Keren browser. Most of these programs inject themselves into your Web browser to monitor your interactions with online advertisements; this function superficially is similar to that of some kinds of spyware. As a consequence, many security products may detect ApptoU or other Installerex programs by the Trojan classification, although malware researchers currently classify ApptoU as adware.

ApptoU's installation is followed by modifications to your browser that make changes to how your browser displays the Web pages of major search engines. Affected search sites may include Google and Bing, but aren't limited to these two sites. Searches through these sites may display additional advertisements and third party offers from ApptoU, which may modify more than one browser simultaneously to support its advertisements. At the time of this article's writing, malware researchers only have seen Windows browsers modified by ApptoU, such as Firefox, Internet Explorer or Chrome.

Taking Your Searches Back from an Application

ApptoU has no functions of benefit to either you or your overall PC, and malware researchers often find that adware-based advertisements may be points of contact with threatening Web content. It is strongly encouraged for you to remove ApptoU to prevent any unneeded exposure to phishing attacks and other advertisement-circulated PC threats. Fortunately, ApptoU, along with its installer, is detectable by a wide range of diverse anti-malware products. Since ApptoU may install itself to multiple browsers in different formats, unassisted uninstall methods are not suggested, since they take the risk of failing to delete all of ApptoU's software.

PUPs sometimes are installed through less than honest methods, such as bundles with other products. If you are interested in avoiding ApptoU and other PUPs from WebPick Holdings, it behooves you to scan suspicious files with appropriate PC security programs prior to launching them. However, malware researchers also would emphasize the necessity of proper user behavior, which always should strive to evade the kinds of illegal and poor reputation software sites that are most likely to install adware with varying degrees of consent and deception.

ApptoU Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\AApptoU\Ui920cv4.x64.dll File name: Ui920cv4.x64.dll
Size: 473.08 KB (473088 bytes)
MD5: 0aaa8aa88bf41741b808e5ff0e31c644
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\AApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\AppToU\qduKPzz.dll File name: qduKPzz.dll
Size: 424.96 KB (424960 bytes)
MD5: 6aa69b3ea70d78f38ae2086acef1ed11
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\AppToU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptOUu\QOVlsaR1aF.dll File name: QOVlsaR1aF.dll
Size: 424.96 KB (424960 bytes)
MD5: 952942f13dbc671f4e551546e0471e80
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptOUu
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApPtoU\6J_k6g.x64.dll File name: 6J_k6g.x64.dll
Size: 472.06 KB (472064 bytes)
MD5: f37ddae284db97dc68d7c7a74b88687c
Detection count: 60
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApPtoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\JSRc3ESK.x64.dll File name: JSRc3ESK.x64.dll
Size: 472.57 KB (472576 bytes)
MD5: 23e593d2410c24eaa7dce33e16d40627
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\Application Data\AppTOU\1y.dll File name: 1y.dll
Size: 426.49 KB (426496 bytes)
MD5: 46fefbf1dbbf845fb955f42d3a3bedc0
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Application Data\AppTOU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\GtA.x64.dll File name: GtA.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 9c82845a161207474e7f05f842dd1d56
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\dby.dll File name: dby.dll
Size: 425.98 KB (425984 bytes)
MD5: f00bdcc5143c31bf2571d037a0a1950f
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\EfPa.x64.dll File name: EfPa.x64.dll
Size: 477.18 KB (477184 bytes)
MD5: 48fe671275e7439fd2de379aea328df6
Detection count: 13
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoUU\_2qe9m.x64.dll File name: _2qe9m.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: ae8b7015a77f33d1a303094d9dd197c2
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoUU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\30nwpDh02.x64.dll File name: 30nwpDh02.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 190fb09e5b3bf44bbc88ae27e2382e5e
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\Fnw6Jl.x64.dll File name: Fnw6Jl.x64.dll
Size: 473.6 KB (473600 bytes)
MD5: f90c91d01b5691a134dcad9b413f9d87
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
C:\ProgramData\PPTT2PNG\b.dll File name: b.dll
Size: 425.47 KB (425472 bytes)
MD5: ed050514551cc5895363642e57c6de5c
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\PPTT2PNG\b.dll
Group: Malware file
Last Updated: August 25, 2021
%ALLUSERSPROFILE%\ApptoU\L3y.dll File name: L3y.dll
Size: 425.47 KB (425472 bytes)
MD5: 29acf3076e8994a1495e75d73b801def
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
%ALLUSERSPROFILE%\ApptoU\bPEL.dll File name: bPEL.dll
Size: 424.44 KB (424448 bytes)
MD5: 5d8ecfaafe0b67a12c3be0a86e76bba0
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\ApptoU
Group: Malware file
Last Updated: April 10, 2014
C:\ProgramData\apptou\qX.exe MD5: 31660bea6df0ed8414f97f7f9aa49d9e File name: C:\ProgramData\apptou\qX.exe MD5: 31660bea6df0ed8414f97f7f9aa49d9e
Mime Type: unknown/exe MD5: 31660bea6df0ed8414f97f7f9aa49d9e
Group: Malware file
C:\ProgramData\apptou\_z6lmrwXrj.exe File name: C:\ProgramData\apptou\_z6lmrwXrj.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\apptou\gG95.exe File name: C:\ProgramData\apptou\gG95.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\apptou\gG95.dll File name: C:\ProgramData\apptou\gG95.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\gG95.x64.dll File name: C:\ProgramData\apptou\gG95.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\Km.exe File name: C:\ProgramData\apptou\Km.exe
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\apptou\Km.dll File name: C:\ProgramData\apptou\Km.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\Km.x64.dll File name: C:\ProgramData\apptou\Km.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\qX.exe File name: C:\ProgramData\apptou\qX.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\apptou\qX.dll File name: C:\ProgramData\apptou\qX.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\qX.x64.dll File name: C:\ProgramData\apptou\qX.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\_z6lmrwXrj.dll File name: C:\ProgramData\apptou\_z6lmrwXrj.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\apptou\_z6lmrwXrj.x64.dll File name: C:\ProgramData\apptou\_z6lmrwXrj.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{3E6B5B5A-8E5E-9D18-117F-F41316EC31F4}

Additional Information

The following URL's were detected:
APptoUAppToUApptOUApptoU
Loading...