Threat Database Backdoors Backdoor:Win32/Zegost.H

Backdoor:Win32/Zegost.H

By Sumo3000 in Backdoors

Threat Scorecard

Ranking: 16,339
Threat Level: 60 % (Medium)
Infected Computers: 633
First Seen: October 13, 2011
Last Seen: August 31, 2023
OS(es) Affected: Windows

Backdoor:Win32/Zegost.H is a hazardous remote control backdoor Trojan which enables cybercriminals to gain remote and secret access to the compromised PC systems. Backdoor:Win32/Zegost.H may be used to perform distributed denial of service (DDoS) attacks. Backdoor:Win32/Zegost.H may also be used to install other malware infections or fake software programs. Backdoor:Win32/Zegost.H may open ports on the infected computer and thus possible cause further attacks. Remove Backdoor:Win32/Zegost.H immediately after detection.

SpyHunter Detects & Remove Backdoor:Win32/Zegost.H

File System Details

Backdoor:Win32/Zegost.H may create the following file(s):
# File Name MD5 Detections
1. hexterms.exe a512281a5668d39698147c056bc5ffb9 5
2. cgoegm.exe 8b4ba191fec40a8bec0f487603f9511a 1
3. file.exe 9a0d7d4d9dcf54db770d0e37443ecf40 1
4. file.exe 8a3e709f29a8f85f41f165f7eb831d69 1
5. file.exe 8d0057024b3a29a1314896e83562ac68 0
6. file.exe 0c2b1d94ddc1eb45f627b879097a5442 0

Registry Details

Backdoor:Win32/Zegost.H may create the following registry entry or registry entries:
Regexp file mask
%PROGRAMFILES%\Google\svchots.exe
%TEMP%\WatchFolder.exe
%WINDIR%\BJ.exe
%WINDIR%\Help\360Safx.exe
%WINDIR%\svchosvt.exe
%WINDIR%\SysWOW64\lytrym.exe
%WINDIR%\SysWOW64\systen.exe
%WINDIR%\SysWOW64\zqbzqy.exe
%WINDIR%\Terms.exe
SOFTWARE\Wow6432Node\FuckYou
SOFTWARE\Wow6432Node\Microsoft\Comfastuserswitchingcompatibility70

Directories

Backdoor:Win32/Zegost.H may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\Storm\update\%SESSIONNAME%
%ALLUSERSPROFILE%\DRM\%SESSIONNAME%
%ALLUSERSPROFILE%\Storm\update\%SESSIONNAME%

Trending

Most Viewed

Loading...