We checked up the file CNMPGBAD.EXE and found it hazardous.
The file CNMPGBAD.EXE must be deleted from the system immediately.
Kill the process CNMPGBAD.EXE and remove CNMPGBAD.EXE from the Windows startup.
Malware Analysis of CNMPGBAD.EXE
Full path on a computer: %TEMP%\CNMPGBAD.EXE
Detected by UnHackMe:
CNMPGBAD.EXE
Default location: %TEMP%\CNMPGBAD.EXE
Removal Results: Success
Number of reboot: 1
CNMPGBAD.EXE is known as:
Trojan Downloader
How to quickly detect CNMPGBAD.EXE presence?
Files:
- %TEMP%\SBDIEEI\SPXPMHO\WOW.DLL
- %APPDATA%\MICROSOFT\SYSTEMCERTIFICATES\MY\CERTIFICATES\DECC63C50178665AB8D81149C70E50981C6098D4
- %APPDATA%\MICROSOFT\CRYPTO\RSA\S-1-5-21-2052111302-484763869-725345543-1003\A1B62797243127BD5D5236996753F08E_23EF5514-3059-436F-A4A7-4CEFAAB20EB1
- %TEMP%\ILCNMPGB.EXE:DEL
- %TEMP%\CNMPGBAD.EXE