Home Malware Programs Trojans Application.Apophis_Spy

Application.Apophis_Spy

Posted: December 9, 2009

Threat Metric

Threat Level: 8/10
Infected PCs: 220
First Seen: April 13, 2011
OS(es) Affected: Windows

Application.Apophis_Spy is a malicious Trojan that represents a security risk for the compromised computer or its network environment. Application.Apophis_Spy contains a remote keylogger that runs in the background, recording all the users keystrokes. Once the keystrokes are logged, they are saved in the machine for later retrieval, or immediately sent to a hacker. Application.Apophis_Spy poses a severe threat to PC security and should be removed from the system immediately.

Aliases

Worm/AutoRun.MB [AVG]W32/AutoIt.GO!worm [Fortinet]Trojan-Downloader.Win32.Banload [Ikarus]Trojan/Win32.Downloader [AhnLab-V3]Win32.HLLW.Autoruner.19532 [DrWeb]W32/AutoIt-JY [Sophos]Worm.Win32.AutoIt.va [Kaspersky]BV:Malware-gen [Avast]W32.SillyFDC [Symantec]W32/Trojan-juke-based!Maximus [F-Prot]Win32/Autoit.GO [NOD32]W32/Autorun.worm!nu [McAfee]Generic Backdoor [Panda]Generic26.BRRD [AVG]W32/Delf.ABL!tr [Fortinet]
More aliases (218)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\tmp1589eb14\KillEXE.exe File name: KillEXE.exe
Size: 237.05 KB (237056 bytes)
MD5: f4433398965a9be095e4b7126fad9609
Detection count: 133
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\tmp1589eb14
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\SysWow64\nsy4415.dll File name: nsy4415.dll
Size: 1.29 MB (1290240 bytes)
MD5: 0bca006592a1710dbc8813593df055d7
Detection count: 96
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\SysWow64
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\system32\9dace4f8.dll File name: 9dace4f8.dll
Size: 2.62 MB (2627584 bytes)
MD5: 68889a25bdb6e40c347f5c3b168f8582
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 18, 2011
%APPDATA%\SysWin\lsass.exe File name: lsass.exe
Size: 201.72 KB (201728 bytes)
MD5: 194470237e14d61caa4e8a4faa5f05db
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SysWin
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\system32\hkicmd.exe File name: hkicmd.exe
Size: 495.61 KB (495616 bytes)
MD5: 373ee61eb6c04fc71eba7159e30a990e
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\ipdili.dll File name: ipdili.dll
Size: 110.59 KB (110592 bytes)
MD5: 0d5f093c799aa96499d867bcbd915dfd
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: April 15, 2011
c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe File name: acleaner.exe
Size: 45.33 KB (45335 bytes)
MD5: 420460f50dc229df4a5a278d5a98a5e5
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\svchost.exe File name: svchost.exe
Size: 69.2 KB (69200 bytes)
MD5: 87177979a1140db95f3cba50206220fe
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: August 18, 2011
%WINDIR%\scvost.com File name: scvost.com
Size: 373.77 KB (373777 bytes)
MD5: 8279d1a289a3505eb981e9052b4604a9
Detection count: 5
File type: Command, executable file
Mime Type: unknown/com
Path: %WINDIR%
Group: Malware file
Last Updated: December 28, 2012
Loading...