Hesive.b is a backdoor that provides the attacker with unauthorized remote access to the compromised computer. It allows the intruder to download, upload and run arbitrary files, execute system commands, terminate running processes, modify system configuration through the registry, get system and network information. Hesive.b inject malicious code into legitimate system processes. It also uses a rootkit to hide all its files and registry entries.
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesykheptdHKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRootLEGACY_ZYKHEPTDHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesdmserverParametersServiceDLL=percentSystempercentzykheptd.dllHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun(default)=rundll32.exe [filename], do98work