Home Malware Programs Backdoors Backdoor: Win32/Hostil.F

Backdoor: Win32/Hostil.F

Posted: April 21, 2011

Backdoor:Win32/Hostil.F is a malicious backdoor trojan that enables unauthorized access and control to an infected computer.
Backdoor:Win32/Hostil.F helps a hacker obtain access to a computer system secretly without user's consent and awareness. Backdoor:Win32/Hostil.F acts as a fake anti-spyware program that shows tricky security warnings and false scan results. It is recommended to remove Backdoor: Win32/Hostil.F from your PC system immediately after its detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\neck10y11p61q4tk2ny0y30782708y184
    2 %AppData%\oxy.exe
    3 %CommonAppData%\neck10y11p61q4tk2ny0y30782708y184
    4 %Temp%\neck10y11p61q4tk2ny0y30782708y184
    5 %Templates%\neck10y11p61q4tk2ny0y30782708y184

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exeHKEY_CURRENT_USER\Software\Classes\.exe\DefaultIconHKEY_CURRENT_USER\Software\Classes\.exe\shellHKEY_CURRENT_USER\Software\Classes\.exe\shell\openHKEY_CURRENT_USER\Software\Classes\.exe\shell\open\commandHKEY_CURRENT_USER\Software\Classes\.exe\shell\runasHKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\commandHKEY_CURRENT_USER\Software\Classes\exefileHKEY_CURRENT_USER\Software\Classes\exefile\DefaultIconHKEY_CURRENT_USER\Software\Classes\exefile\shellHKEY_CURRENT_USER\Software\Classes\exefile\shell\openHKEY_CURRENT_USER\Software\Classes\exefile\shell\open\commandHKEY_CURRENT_USER\Software\Classes\exefile\shell\runasHKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command[HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command] (Default) = ""%AppData%\oxy.exe" -a "%1" %*" IsolatedCommand = ""%1" %*"[HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command] (Default) = ""%1" %*" IsolatedCommand = ""%1" %*"[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_CURRENT_USER\Software\Microsoft\Windows] Identity = 0xDBFC8B3CHKEY..\..\..\..{RegistryKeys}ctfmon.exe = "%System%\ctfmon.exe"
Loading...