KENAD.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

KENAD.EXE – Trojan Delf removal

FileMD5Virus Alias
KENAD.EXE 49bd1b4d44cc737c2a738fde9c532daa Trojan Delf
KENAD.EXE 49bd1b4d44cc737c2a738fde9c532daa Trojan Generic
KENAD.EXE 49bd1b4d44cc737c2a738fde9c532daa Trojan Eldorado
KENAD.EXE 49bd1b4d44cc737c2a738fde9c532daa Trojan Siggen
KENAD.EXE 49bd1b4d44cc737c2a738fde9c532daa Trojan Agent

KENAD.EXE size: 861940 bytes
KENAD.EXE hash: 49BD1B4D44CC737C2A738FDE9C532DAA

Created files:

%Program Files%\Zpsa\Kenad.exe
%Program Files%\Zpsa\Ozac\Dexo.dll
%Program Files%\Zpsa\Peqw.exe
%TEMP%\g823\Crintsoft.MiniLyrics.v6.5.278.Incl.Keygen-JANOSiK.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Zpsa\Kenad.exe

Detected by UnHackMe:

KENAD.EXE
Default location: %PROGRAM FILES%\ZPSA\KENAD.EXE

Dropper information:
MD5: 2102c028e9e83b6d874878887420f518
File size: 3999456 bytes

Leave a Reply