NOTEPAT.EXE – Trojan ZBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NOTEPAT.EXE – Trojan ZBot removal

File MD5 Virus Alias
NOTEPAT.EXE 5c492c6300fd9def233bfaa56fb6b0f2 Trojan ZBot
NOTEPAT.EXE 5c492c6300fd9def233bfaa56fb6b0f2 Trojan Generic
NOTEPAT.EXE 5c492c6300fd9def233bfaa56fb6b0f2 Trojan Downloader

NOTEPAT.EXE size: 180000 bytes
NOTEPAT.EXE hash: 5C492C6300FD9DEF233BFAA56FB6B0F2

Created files:

%TEMP%\notepat.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\chrome_frame_helper.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\chrome_launcher.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\Installer\setup.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\nacl64.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.172\chrome_frame_helper.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.172\chrome_launcher.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.172\delegate_execute.exe
%UserProfile%\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.172\Installer\setup.exe
%UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

Detected by UnHackMe:

NOTEPAT.EXE
Default location: %TEMP%\NOTEPAT.EXE

Dropper information:
MD5: 67315e9dc6721f15be4079c6168c961d
File size: 2067857 bytes

Leave a Reply