How to remove apr.exe

apr.exe

The module apr.exe has been detected as Trojan.Kryptik

apr.exe

apr.exe is a Windows file recorded in the ThreatInfo database. It is associated with ActivePresenter. The reported company name is Atomi Systems, Inc.. The current detection status is Trojan.Kryptik, based on the latest analysis from 2021-03-22 21:47:23 (5 years ago).

If apr.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Kryptik.

Product Name: ActivePresenter
Company Name: Atomi Systems, Inc.
MD5: a0f65e13363b4e3a5fe2e559753efe61
Size: 1 MB
First Published: 2021-03-22 21:47:23 (5 years ago)
Latest Published: 2021-03-22 21:47:23 (5 years ago)
Status: Trojan.Kryptik (on last analysis)
Analysis Date: 2021-03-22 21:47:23 (5 years ago)
%programfiles%

ThreatInfo has observed apr.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is United States with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for apr.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

apr.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0006afc4

PE Sections:

Name Size of data MD5
.text 453632 9e1d5019a64075a30dea1002b06e6ef9
.rdata 9728 27128c0729d406cae6c037c7255e452c
.data 11264 eb82f45bdd20cfb1173d267a8a4c97c3
.jpeg 658432 092aa10ea210d73f8cdaa0916c5a5bfe
.rsrc 33280 77d477c538bf5089b430f8260cad3331

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for apr.exe