Malware

What is “Win32/PowerPool.NAA”?

Malware Removal

The Win32/PowerPool.NAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PowerPool.NAA virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

www.sdvro.net

How to determine Win32/PowerPool.NAA?


File Info:

crc32: 8EC20FC2
md5: 448838b2a60484ee78c2198f2c0c9c85
name: upload_file
sha1: f2c43a01cabaa694228f5354ea8c6bcf3b7a49b3
sha256: 64d78eec46c9ddd4b9a366de62ba0f2813267dc4393bc79e4c9a51a9bb7e6273
sha512: 9e532af06e5f4764529211e8c5c749baa7b01c72f11b603218c3c08d70cf1e732f8d9d81ec257ca247aaa96d1502150a2f402b1b3914780b6344222b007dd53f
ssdeep: 3072:PGA5q4Xmco7ciR7BiU+q+TESaiQ4RHpxJdW:O0qtUYBiU+qRiQy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/PowerPool.NAA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44001732
CAT-QuickHealTrojanSpy.KeyLogger
McAfeeSlothfulMedia
CylanceUnsafe
ZillyaTrojan.Keylogger.Win32.4
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/KeyLogger.219d3da2
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2a6048
ArcabitTrojan.Generic.D29F69C4
InvinceaMal/Generic-R + Troj/Spy-BCQ
CyrenW32/Trojan.ENTX-1947
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.KeyLogger.buiu
BitDefenderTrojan.GenericKD.44001732
NANO-AntivirusTrojan.Win32.KeyLogger.hxxsrs
ViRobotTrojan.Win32.S.Agent.117760.NV
Ad-AwareTrojan.GenericKD.44001732
SophosTroj/Spy-BCQ
ComodoTrojWare.Win32.ButeRat.PP@4roeaa
DrWebBackDoor.Siggen2.3283
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan.GenericKD.44001732 (B)
IkarusTrojan-PWS.Win32.Zbot
JiangminTrojanSpy.KeyLogger.nmw
eGambitUnsafe.AI_Score_87%
AviraTR/Spy.KeyLogger.jxpwo
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.KeyLogger
AegisLabTrojan.Win32.KeyLogger.l!c
ZoneAlarmTrojan-Spy.Win32.KeyLogger.buiu
GDataTrojan.GenericKD.44001732
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.C4204765
BitDefenderThetaGen:NN.ZexaF.34298.huW@aS4ne2pi
ALYacTrojan.Keylogger.Agent
VBA32Trojan.Wacatac
MalwarebytesTrojan.KeyLogger
ESET-NOD32a variant of Win32/PowerPool.NAA
TrendMicro-HouseCallTrojanSpy.Win32.SLOTHFULMEDIA.THJOBBO
RisingTrojan.Generic@ML.88 (RDMK:iFyePf7oybipvNIZHI27qQ)
SentinelOneDFI – Malicious PE
FortinetW32/SlothFulMedia.9C8B!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Spy.cac

How to remove Win32/PowerPool.NAA?

Win32/PowerPool.NAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment