Solved! Use 6TO4V32.DLL (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

6TO4V32.DLL – Trojan Artemis removal

File MD5 Virus Alias
6TO4V32.DLL bd04ffff82d3c94ab6ae19fd09cebb69 Trojan Artemis
6TO4V32.DLL bd04ffff82d3c94ab6ae19fd09cebb69 Trojan CI
6TO4V32.DLL bd04ffff82d3c94ab6ae19fd09cebb69 Trojan Agent

6TO4V32.DLL size: 61440 bytes
6TO4V32.DLL hash: BD04FFFF82D3C94AB6AE19FD09CEBB69

Created files:

%SysDir%\6to4v32.dll
%SysDir%\daqdrv.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\6to4\Type: 20010000
HKLM\System\CurrentControlSet\Services\6to4\Start: 02000000
HKLM\System\CurrentControlSet\Services\6to4\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\6to4\DisplayName: 4E006500740077006F0072006B002000530065006300750072006900740079000000
HKLM\System\CurrentControlSet\Services\6to4\ImagePath: %SystemRoot%\System32\svchost.exe -k netsvcs
HKLM\System\CurrentControlSet\Services\6to4\Description: 570069006E0064006F007700730020004E006500740077006F0072006B0020005300650063007500720069007400790020004D0061006E006100670065006D0065006E007400200053006500720076006900630065000000
HKLM\System\CurrentControlSet\Services\6to4\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00360074006F0034007600330032002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\daqdrv\Type: 01000000
HKLM\System\CurrentControlSet\Services\daqdrv\Start: 03000000
HKLM\System\CurrentControlSet\Services\daqdrv\DisplayName: daqdrv
HKLM\System\CurrentControlSet\Services\daqdrv\ImagePath: %WinDir%\System32\daqdrv.sys
HKLM\System\CurrentControlSet\Services\daqdrv\Description: daqdrv

Detected by UnHackMe:

6TO4V32.DLL
Default location: %SYSDIR%\6TO4V32.DLL

Dropper information:
MD5: 1d156d8878b79f542c219d64d991d1c1
File size: 88064 bytes

Leave a Reply