Home Malware Programs Trojans Trojan.Tapaoux

Trojan.Tapaoux

Posted: November 24, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 14
First Seen: November 24, 2011
Last Seen: August 22, 2018
OS(es) Affected: Windows

Trojan.Tapaoux is a harmful Trojan that downloads and installs additional malware threats onto the computer system. Trojan.Tapaoux covers itself as a normal Windows service and writes itself into startup process and Windows Registry. Trojan.Tapaoux tries to exploit the Adobe Reader 'CoolType.dll' TTF Font Remote Code Execution Vulnerability (BID 43057). Once the Trojan is executed, it adds a DLL file and installs itself as a system driver. Trojan.Tapaoux also checks for security-related software by looking for certain registry subkeys. If Trojan.Tapaoux finds any of the appropriate registry subkeys or processes, it will exit. Trojan.Tapaoux then tries to connect to certain domains. If Trojan.Tapaoux connects successfully, it will download and install potentially malicious files onto the affected machine and execute them. Also, Trojan.Tapaoux installs a rootkit that modifies the System Service Dispatch Table (SSDT) in order to disguise itself.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 43.52 KB (43523 bytes)
MD5: c2915bece3269b7a8dac1e2745063b49
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: April 4, 2018
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\iexp\expsrv32.exe File name: expsrv32.exe
Size: 113.43 KB (113432 bytes)
MD5: 653ffc574a13c4bc8337c688124fd0bf
Detection count: 58
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\iexp\expsrv32.exe
Group: Malware file
Last Updated: June 26, 2020
vpmde.dll File name: vpmde.dll
Size: 166.68 KB (166680 bytes)
MD5: 566e92f79497a3c6136b815c9960b898
Detection count: 57
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
file.dll File name: file.dll
Size: 174.87 KB (174872 bytes)
MD5: 387128c489a66a70c7ed76b27f1dd4e2
Detection count: 17
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: November 28, 2011
6619a4ff7f0478f8c15fc0391651a1694afe876d25ebd07e3da08167e4f0b3d3.exe File name: 6619a4ff7f0478f8c15fc0391651a1694afe876d25ebd07e3da08167e4f0b3d3.exe
Size: 370.87 KB (370872 bytes)
MD5: 60af79fb0bd2c9f33375035609c931cb
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 14, 2021
%System%\schechk.exe File name: %System%\schechk.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\hwpolicy.dll File name: %System%\hwpolicy.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%System%\schechk.bin File name: %System%\schechk.bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
%System%\schechk.sys File name: %System%\schechk.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\imagepk.sys File name: %System%\imagepk.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\npidsz4.sys File name: %System%\npidsz4.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\securx86.sys File name: %System%\securx86.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\hwpolicy.sys File name: %System%\hwpolicy.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\sscore1.sys File name: %System%\sscore1.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\sisraid3.sys File name: %System%\sisraid3.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\expsrv32.sys File name: %System%\expsrv32.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\ql5200.sys File name: %System%\ql5200.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EpsonK200

Additional Information

The following URL's were detected:
ebizcentres.com/system32/list4/yahoo/banne[DELETED]re.policy-forums.org/ol/yahoo/banne[DELETED]

Related Posts

Loading...