Home Malware Programs Trojans Trojan.Ransom.Hexzone

Trojan.Ransom.Hexzone

Posted: June 13, 2011

Trojan.Ransom.Hexzone is known to be a group of Trojan files that attempt to hide themselves on a PC. After installed, Trojan.Ransom.Hexzone may render deceptive alert messages and then open up a system to an outside attacker. Trojan.Ransom.Hexzone may be the gateway for a hacker to steal stored information on an infected PC. The threat of Trojan.Ransom.Hexzone may be removed successfully with an updated spyware removal application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ac_VZHEH4bVx.dll
    2 aiXNb_YjRFus7HUGf.dll
    3 aKAuEWkfC.dll
    4 amUB7nWLj2GlV_6yXwT_.dll
    5 aO2sUkDmi9WxvwTJr.dll
    6 aX6kXZo_ner.dll
    7 aZFQEU7nWEWU.dll
    8 gyxlib.dll
    9 helper32.dll
    10 rjxlib.dll
    11 testdll.dll
    12 tprlib.dll
    13 winhelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ExHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{9EC90B7A-E7D9-488F-84CD-C018FDA695F3}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{1381CD50-001A-7591-0BA1-BCDE6A31109C}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{8EC283D0-540C-B7BE-D163-DDCC19C53A9B}HKEY..\..\..\..{RegistryKeys}{0B62BEBA-FE11-41A7-B2D8-5A6437525101}{1408E208-2AC1-42D3-9F10-78A5B36E05AC}{44D67555-2D4E-4227-AB49-E509D025C487}{A60B986B-4FED-44F4-A830-47CE85A85E88}{DE6532E2-FD43-4DFB-9108-14140DBAB88C}{F31776F2-6138-4179-B062-6C00E71589F7}
Loading...