Win32.Notpa

Backdoor Trojan program Win32.Notpa will gain access to a system by surreptitious means. It has the ability to remain hidden.  It will hide in the computer’s registries making it difficult to detect.  However, here are some of its fingerprints:
4e2b555b27647a1c…
8cc73d4a43ba1316…
25aa2aa7e1bc8ef2…
38ef03ce0fbcfd37…
92c9040891952dad…
706a2e86e0d72ad8…
455d0785fa6bd6c0…
52815f56b44adae1…
a04af2d08061c395…
d06d3f136e726ce6…
326549d9abd44c67…
9cd41bb740874932…
dcda6da0879ddee9…

Its MD5 is 5e1f1723c04d6a3f87dd1d0c2c1d2467 and it has a file size of 10240 bytes

Related Files:
1134054079.exe
1476552388.exe
backdoor.exe
icqnuke.exe
readme.exe
notpa.exe
backdoor.txt
notpa.exe in Windows\
[%PROFILE_TEMP%]\tt_unadd.inf
[%SYSTEM%]\SWRT01.dll
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Per Adulti.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Previsioni Meteo.lnk
[%DESKTOP%]\Previsioni Meteo.lnk
[%PROGRAM_FILES%]\Internet Explorer\MUI\yybar.exe
[%PROGRAM_FILES%]\ybar.exe
[%STARTMENU%]\Per Adulti.lnk
[%STARTMENU%]\Previsioni Meteo.lnk
[%SYSTEM%]\antiwpa.dll

AKA:
Backdoor.Notpa
Backdoor.Zemac.d
BackDoor-AR
Win32/BackDoor.2_02
Win32/Notpa.A
Win32/Zemac.D
Win95/ICQNuke98.Trojan

Category:
Backdoor Trojan

Recommended Action:
Remove at once.

For manual removal of Win32.Notpa, kill these processes:
-1134054079.exe
1476552388.exe
backdoor.exe
icqnuke.exe
readme.exe
notpa.exe.

Then, go and search for the following files and remove them:
-1134054079.exe
1476552388.exe
backdoor.exe
backdoor.txt
icqnuke.exe
readme.exe. notpa.exe in Windows\.

For complete spyware removal, there is ZookaWare PC Cleaner.  With ZookaWare PC Cleaner, there is a free scan to determine the level of infection. Then is the process of removal.   ZookaWare PC Cleaner is an award-winning anti-spyware application that can remove any and all spyware, usually in one scan, guaranteed.

Download Free Scan
Cyberlab runs on Windows Vista, 7, 8 and 10. It has no ads, popups or bundled software and fully uninstalls by clicking Start > All Programs > select Cyberlab and click Uninstall.

Leave a Reply

Your email address will not be published.

Products

Contact

css.php