Home Malware Programs Adware Norpalla

Norpalla

Posted: March 12, 2014

Threat Metric

Ranking: 13,377
Threat Level: 2/10
Infected PCs: 2,722
First Seen: March 12, 2014
Last Seen: August 29, 2023
OS(es) Affected: Windows


Norpalla Screenshot 1Norpalla is adware that may declare to make the PC user's Internet surfing activity better and save time and money by delivering deals, discount coupons, offers and sales. Norpalla may show random advertisements and messages with a pop-up box on the computer, which may encompass various offers including discount coupons, sponsored links, banner ads and video related ads, 'pop-unders' or interstitial ads based on the computer user's requests when he is surfing on the Internet. After installation, Norpalla may embed a browser add-on, plug-in or browser extension to all the Web browsers such as Internet Explorer, Google Chrome and Mozilla Firefox installed on the PC. Norpalla may propagate and invade the PC through bundled free software that computer users can download from suspicious download websites on the Internet.

Norpalla Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Norpalla\bin\utilNorpalla.exe File name: utilNorpalla.exe
Size: 348.44 KB (348448 bytes)
MD5: 0283edc86a8b56a922e93b7a95ae948c
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Norpalla\bin
Group: Malware file
Last Updated: April 17, 2014
%PROGRAMFILES(x86)%\Norpalla\Norpalla.FirstRun.exe File name: Norpalla.FirstRun.exe
Size: 1.75 MB (1757472 bytes)
MD5: f30bd621cb5ecd4873babb0b73a87b57
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Norpalla
Group: Malware file
Last Updated: April 17, 2014
system32\drivers\{5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys File name: {5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys
Size: 60.08 KB (60088 bytes)
MD5: c6f481658f7079bae73085012b702190
Detection count: 50
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 7, 2014
system32\drivers\{5906ab0f-5417-45a6-a4f5-8bc38ae936d5}t64.sys File name: {5906ab0f-5417-45a6-a4f5-8bc38ae936d5}t64.sys
Size: 60.08 KB (60088 bytes)
MD5: c532534baa5650cc7a963ffc335b9678
Detection count: 13
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 7, 2014
system32\drivers\{5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys File name: {5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys
Size: 60.08 KB (60088 bytes)
MD5: 5e57a31417d99f03aef4253e72345f68
Detection count: 12
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys File name: {5906ab0f-5417-45a6-a4f5-8bc38ae936d5}Gt64.sys
Size: 60.08 KB (60088 bytes)
MD5: 5e30607d18d99fd25b9426a91466033c
Detection count: 11
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 7, 2014
%WINDIR%\System32\drivers\{5906ab0f-5417-45a6-a4f5-8bc38ae936d5}t.sys File name: {5906ab0f-5417-45a6-a4f5-8bc38ae936d5}t.sys
Size: 55.22 KB (55224 bytes)
MD5: 41752032871a6ec303c198c28c9bef8c
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: July 7, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{18b20944-f54e-4509-88fa-f0ad137bf8de}{DD85F972-6C6F-482E-A3DB-82FABC0AA142}{E766A177-5525-448E-8CA8-76B0E3CC7295}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{18B20944-F54E-4509-88FA-F0AD137BF8DE}Software\Microsoft\Internet Explorer\Approved Extensions\{78F5A1E7-DD0D-49F9-871B-1889C9729861}SOFTWARE\Microsoft\Tracing\Norpalla_RASAPI32SOFTWARE\Microsoft\Tracing\Norpalla_RASMANCSSOFTWARE\Microsoft\Tracing\updateNorpalla_RASAPI32SOFTWARE\Microsoft\Tracing\updateNorpalla_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{18B20944-F54E-4509-88FA-F0AD137BF8DE}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18B20944-F54E-4509-88FA-F0AD137BF8DE}Software\NorpallaSOFTWARE\Wow6432Node\Microsoft\Tracing\Norpalla_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Norpalla_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateNorpalla_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateNorpalla_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{18b20944-f54e-4509-88fa-f0ad137bf8de}SOFTWARE\Wow6432Node\NorpallaSYSTEM\ControlSet001\services\eventlog\Application\Update NorpallaSYSTEM\ControlSet001\services\Update NorpallaSYSTEM\ControlSet002\services\eventlog\Application\Update NorpallaSYSTEM\ControlSet002\services\Update NorpallaSYSTEM\CurrentControlSet\services\eventlog\Application\Update NorpallaSYSTEM\CurrentControlSet\services\Update NorpallaHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Norpalla

Additional Information

The following directories were created:
%PROGRAMFILES%\Norpalla%PROGRAMFILES(x86)%\Norpalla%TEMP%\Norpalla
The following URL's were detected:
Norpalla
Loading...