I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free Download Fully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE – Trojan Banker removal
File | MD5 | Virus Alias |
---|---|---|
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE | c1ff60861893c1a44c855e75d6e817c4 | Trojan Banker |
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE | c1ff60861893c1a44c855e75d6e817c4 | Trojan SuspiciousFile |
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE | c1ff60861893c1a44c855e75d6e817c4 | Trojan Agent |
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE size: 1622649 bytes
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE hash: C1FF60861893C1A44C855E75D6E817C4
Created files:
%Program Files%\Bemo\Ditau\Evnoy.dll
%Program Files%\Bemo\Lfuoo.exe
%Program Files%\Bemo\Naaib.exe
%TEMP%\g84C\Kudrsoft.Multi-Page.TIFF.Editor.v1.4.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Bemo\Naaib.exe
Detected by UnHackMe:
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE
Default location: %TEMP%\G84C\KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE
Dropper information:
MD5: 54cb1dac4e8e5579a7c2ef8fc5227ea9
File size: 3567540 bytes