Home Malware Programs Trojans Trojan.Notepices

Trojan.Notepices

Posted: August 11, 2016

Threat Metric

Ranking: 16,605
Threat Level: 8/10
Infected PCs: 36,284
First Seen: August 11, 2016
Last Seen: March 2, 2025
OS(es) Affected: Windows


Trojan.Notepices is a persistent threat that works in the background and modifies the behavior of the user's default Web browser. The changes that Trojan.Notepices may impose may become rather annoying, because the user's Web browser may redirect them to a suspicious website that hosts disturbing images and media content randomly, which may not be something you want to see while browsing the Web. One of the pages that Trojan.Notepices redirects to is hxxp://krawzasireglem.ru, a redirect portal that may send the user to several other pages that may host irrelevant or disturbing media content.

The good news is that Trojan.Notepices' only ability is to force random Web browser redirects, as well as sometimes open the default system Web browser and send the user to a page like hxxp://krawzasireglem.ru automatically. While this behavior is certainly annoying, it isn't directly unsafe. However, such Trojans may often be used to transfer users to websites that host threatening software or exploit kits, and that's why users are advised to take the necessary measures to eliminate Trojan.Notepices as soon as possible.

This threat may be introduced to computers when their users install a low-quality checkers game that goes by the name 'GameLauncher.' Several other games and applications also may be linked to this threat – Draughts, SevilerGame, Seviler2DGame and SimpleNotepad. We advise users who've recently installed one of the applications listed above to run an anti-malware scanner immediately to ensure that the Trojan.Notepices wasn't dropped on their computer. If you are suffering from the Web browser redirects that this Trojan causes, then running a reputable anti-malware software suite is the correct way to resolve the issue.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\GameLauncher\Seviler\Seviler.exe File name: Seviler.exe
Size: 683 KB (683008 bytes)
MD5: 64c8a58a95040aef41a12effae46b72f
Detection count: 213
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\GameLauncher\Seviler
Group: Malware file
Last Updated: November 17, 2016
%APPDATA%\SimpleNotepad4\SimpleNoteApp3.exe File name: SimpleNoteApp3.exe
Size: 1.01 MB (1019904 bytes)
MD5: 8db9d1ec45022d7425dec51113d355b6
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SimpleNotepad4
Group: Malware file
Last Updated: March 6, 2020
%APPDATA%\SimpleNotepad4\SimpleNoteApp5.exe File name: SimpleNoteApp5.exe
Size: 2.31 MB (2318336 bytes)
MD5: 5915816400d969cb1851dcd9eeac04a4
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SimpleNotepad4
Group: Malware file
Last Updated: May 15, 2020
%APPDATA%\SimpleNotepad\SimpleNoteApp.exe File name: SimpleNoteApp.exe
Size: 419.84 KB (419840 bytes)
MD5: 473bef5c0105e4e1195909a1fe3db171
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SimpleNotepad
Group: Malware file
Last Updated: August 18, 2016
%APPDATA%\Checkers\Draughts\Draughts.exe File name: Draughts.exe
Size: 2.56 MB (2562216 bytes)
MD5: cebcef853765c397f27ec3f37b435fb1
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Checkers\Draughts
Group: Malware file
Last Updated: August 11, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathSimpleNotepad3.lnkSimpleNotepad4.lnkRegexp file mask%APPDATA%\Checkers\Draughts\Draughts.exe%APPDATA%\GameLauncher\Seviler\Seviler.exeHKEY..\..\..\..{RegistryKeys}Software\SevilerSoftware\SimpleNoteApp3HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SimpleNotepad3SimpleNotepad4

Additional Information

The following directories were created:
%APPDATA%\SimpleNotepad3%APPDATA%\SimpleNotepad4
Loading...