KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE – Trojan Banker

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE – Trojan Banker removal

File MD5 Virus Alias
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE c1ff60861893c1a44c855e75d6e817c4 Trojan Banker
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE c1ff60861893c1a44c855e75d6e817c4 Trojan SuspiciousFile
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE c1ff60861893c1a44c855e75d6e817c4 Trojan Agent

KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE size: 1622649 bytes
KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE hash: C1FF60861893C1A44C855E75D6E817C4

Created files:

%Program Files%\Bemo\Ditau\Evnoy.dll
%Program Files%\Bemo\Lfuoo.exe
%Program Files%\Bemo\Naaib.exe
%TEMP%\g84C\Kudrsoft.Multi-Page.TIFF.Editor.v1.4.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\OALX\Start: 02000000
HKLM\System\CurrentControlSet\Services\OALX\Type: 10000000
HKLM\System\CurrentControlSet\Services\OALX\Description: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\DisplayName: Data Online Transaction Processing Module
HKLM\System\CurrentControlSet\Services\OALX\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\OALX\Group: TDI
HKLM\System\CurrentControlSet\Services\OALX\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\OALX\ImagePath: %Program Files%\Bemo\Naaib.exe

Detected by UnHackMe:

KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE
Default location: %TEMP%\G84C\KUDRSOFT.MULTI-PAGE.TIFF.EDITOR.V1.4.EXE

Dropper information:
MD5: 54cb1dac4e8e5579a7c2ef8fc5227ea9
File size: 3567540 bytes

Leave a Reply