6TO432.DLL – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

6TO432.DLL – Trojan Downloader removal

FileMD5Virus Alias
6TO432.DLL 8fc2b41e3e84891c2495cb58f01f9bf0 Trojan Downloader
6TO432.DLL 8fc2b41e3e84891c2495cb58f01f9bf0 Trojan SuspiciousFile
6TO432.DLL 8fc2b41e3e84891c2495cb58f01f9bf0 Trojan Agent

6TO432.DLL size: 13897 bytes
6TO432.DLL hash: 8FC2B41E3E84891C2495CB58F01F9BF0

Created files:

%SysDir%\6to432
%SysDir%\6to432.dll
%SysDir%\ntdos44.esn

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\6to4\Type: 20000000
HKLM\System\CurrentControlSet\Services\6to4\Start: 02000000
HKLM\System\CurrentControlSet\Services\6to4\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\6to4\DisplayName: 6to4
HKLM\System\CurrentControlSet\Services\6to4\ImagePath: %SystemRoot%\System32\svchost.exe -k netsvcs
HKLM\System\CurrentControlSet\Services\6to4\Description: 6to4
HKLM\System\CurrentControlSet\Services\6to4\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C00360074006F003400330032002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\net8139\Type: 01000000
HKLM\System\CurrentControlSet\Services\net8139\Start: 02000000
HKLM\System\CurrentControlSet\Services\net8139\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\net8139\DisplayName: net8139
HKLM\System\CurrentControlSet\Services\net8139\ImagePath: %WinDir%\System32\ntdos44.esn

Detected by UnHackMe:

6TO432.DLL
Default location: %SYSDIR%\6TO432.DLL

Dropper information:
MD5: d5e32f42cb935be7d7909139fdb484ff
File size: 20593 bytes

Leave a Reply