Backdoor

Backdoor.Staser removal instruction

Malware Removal

The Backdoor.Staser is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Staser virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
ava.ctf.pub
a.tomx.xyz

How to determine Backdoor.Staser?


File Info:

crc32: 5BA65DAA
md5: fac18219e1677269c3c3d8f56c955f06
name: 8085.exe
sha1: 028030984a6ab026c929d8f25a219a7ecca519a4
sha256: c3eb257895a819eab0a0edcbf119ae920d11e8cfb4de302b8f59799e133d31aa
sha512: 3ff726da40fe5f08dde36ea5b193cd709417f6b6f1215c8156da95463903d12f26d8d7805e3c52830155f3f1e243476d67f740e00f9e01bc07d55a6de4a929aa
ssdeep: 3072:PmZBWwd86YpyFnpdp/xVRXEgoY8fv/fNbJzZ7EBMX8Wry6:PTnpyNpH/xVyfY8fv/fX97EYh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: adbrowser
FileVersion: 1, 0, 0, 9
CompanyName: Net.Soft Studio
PrivateBuild: 20120830.01
LegalTrademarks:
Comments:
ProductName: adbrowser
SpecialBuild:
ProductVersion: 1, 0, 0, 9
FileDescription: P2Px7ec8x7ed3x8005x8f85x52a9x6a21x5757
OriginalFilename: adbrowser.EXE
Translation: 0x0804 0x04b0

Backdoor.Staser also known as:

MicroWorld-eScanBackdoor.Zegost.BC
FireEyeGeneric.mg.fac18219e1677269
CAT-QuickHealTrojan.Aksula.A
Qihoo-360Win32/Backdoor.Gh0st.LS
ALYacBackdoor.Zegost.BC
CylanceUnsafe
VIPREWin32.Malware!Drop
SangforMalware
K7AntiVirusTrojan ( 0040f7ad1 )
BitDefenderBackdoor.Zegost.BC
K7GWTrojan ( 0040f7ad1 )
Cybereasonmalicious.9e1677
TrendMicroBKDR_ZEGOST.SML
BitDefenderThetaGen:NN.ZexaF.34122.ni1@aOvpuhhb
CyrenW32/S-3d9bc1fd!Eldorado
BaiduWin32.Trojan.Farfli.bg
TrendMicro-HouseCallBKDR_ZEGOST.SML
AvastWin32:Farfli-CF [Cryp]
ClamAVWin.Trojan.Zegost-7007928-0
GDataBackdoor.Zegost.BC
KasperskyBackdoor.Win32.Farfli.alus
AlibabaBackdoor:Win32/Farfli.04fd2e00
NANO-AntivirusTrojan.Win32.TrjGen.csulmd
AegisLabTrojan.Win32.Kykymber.lUlR
APEXMalicious
RisingBackdoor.Farfli!1.B6C5 (CLOUD)
Ad-AwareBackdoor.Zegost.BC
SophosTroj/Zegost-CV
ComodoTrojWare.Win32.Kryptik.BPVQ@56xtf6
F-SecureBackdoor.BDS/Zegost.mdqcz
DrWebTrojan.Siggen6.27861
ZillyaTrojan.Kryptik.Win32.737668
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftBackdoor.Zegost.BC (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/S-3d9bc1fd!Eldorado
JiangminTrojan/Generic.avrta
WebrootW32.Trojan.Gen
AviraBDS/Zegost.mdqcz
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitBackdoor.Zegost.BC
SUPERAntiSpywareTrojan.Agent/Gen-Siggen
ZoneAlarmBackdoor.Win32.Farfli.alus
MicrosoftBackdoor:Win32/Zegost.AD
AhnLab-V3Trojan/Win32.Scar.R65072
Acronissuspicious
McAfeeBackDoor-FCGT!FAC18219E167
TACHYONBackdoor/W32.Farfli.215905
VBA32BScope.Backdoor.Spy
MalwarebytesBackdoor.Staser
PandaGeneric Malware
ZonerTrojan.Win32.29512
ESET-NOD32Win32/Farfli.ARD
TencentMalware.Win32.Gencirc.10b406f5
YandexTrojan.Kryptik!BskX9BEG55w
IkarusBackdoor.Win32.Zegost
FortinetW32/Farfli.PZA!tr
AVGWin32:Farfli-CF [Cryp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Backdoor.Staser?

Backdoor.Staser removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment