Home Malware Programs Backdoors Backdoor.Win32.Zegost

Backdoor.Win32.Zegost

Posted: October 28, 2010

Backdoor.Win32.Zegost is a malicious backdoor program which operates stealthily to perform corrupt actions. Backdoor.Win32.Zegost is often considered as an integral part of bigger programs like adware. However, Backdoor.Win32.Zegost is a self-sufficient parasite which may act like spyware by stealing financial credentials and other private data. Remove Backdoor.Win32.Zegost immediately by using a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\ACD Systems
    2 %AppData%\ACD Systems\ACDSee
    3 %AppData%\ACD Systems\ACDSee\Imagevx.ddf%SESSIONNAME%

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Comhidserv70\Parameters][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Comhidserv70]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDSERV\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDSERV\0000][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HIDSERV][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDSERV\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDSERV\0000][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HIDSERV]
Loading...