Backdoor Zegost – 64bit.exe – da2537f668942526faa4b8487b635aeb

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Zegost
Also known as: Trojan Agent, Trojan Refroso
SHA256: aca3038b81e4fecf2c6e2c3765999503649885f4a87481172ef24a7dade33df1
SHA1: 7710631f01d31f242bc3798e973b29c734588190
MD5: da2537f668942526faa4b8487b635aeb
File size: 667680 bytes

Created files:

%WinDir%\winr\64bit.exe – Backdoor Zegost

Backdoor Zegost created autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{5B86UL47-NG86-C4XI-TQFP-K0L2WP35R17S}\StubPath: %WinDir%\winr\64bit.exe Restart
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C00770069006E0072005C00360034006200690074002E006500780065000000
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HKLM: 43003A005C00570049004E0044004F00570053005C00770069006E0072005C00360034006200690074002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies: 43003A005C00570049004E0044004F00570053005C00770069006E0072005C00360034006200690074002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HKCU: 43003A005C00570049004E0044004F00570053005C00770069006E0072005C00360034006200690074002E006500780065000000

Leave a Reply