Backdoor

Should I remove “Backdoor.Zegost.BC”?

Malware Removal

The Backdoor.Zegost.BC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Zegost.BC virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Zegost.BC?


File Info:

crc32: 06C8CB4B
md5: 6e674eaf23eb868af5cf9bcf27ed39fe
name: 6E674EAF23EB868AF5CF9BCF27ED39FE.mlw
sha1: dfa4084e966997dd085f817cf2619935401b6dad
sha256: dee83947f1a07bb537bee18f71c18ae2a837661f6d39249e85d00399919820b1
sha512: 6f11b73442fb506e63025a34ad1dc734e1b79956554a7314be571a6ff4a5dd696e78eb9a759825bd11c5e757aec583aa9cb24bd8644d8e0fc1ca9b92b0b52743
ssdeep: 3072:PmZBWwd86YpyFnpdp/xVRXEgoY8fv/fNbJzZ7EBMX8Wry9:PTnpyNpH/xVyfY8fv/fX97EYu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: adbrowser
FileVersion: 1, 0, 0, 9
CompanyName: Net.Soft Studio
PrivateBuild: 20120830.01
LegalTrademarks:
Comments:
ProductName: adbrowser
SpecialBuild:
ProductVersion: 1, 0, 0, 9
FileDescription: P2Px7ec8x7ed3x8005x8f85x52a9x6a21x5757
OriginalFilename: adbrowser.EXE
Translation: 0x0804 0x04b0

Backdoor.Zegost.BC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.27861
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Aksula.A
ALYacBackdoor.Zegost.BC
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.737668
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f7ad1 )
K7AntiVirusTrojan ( 0040f7ad1 )
BaiduWin32.Trojan.Farfli.bg
CyrenW32/S-3d9bc1fd!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Farfli.ARD
ZonerTrojan.Win32.29512
APEXMalicious
AvastWin32:Farfli-CF [Cryp]
ClamAVWin.Trojan.Zegost-7007928-0
KasperskyBackdoor.Win32.Farfli.alus
BitDefenderBackdoor.Zegost.BC
NANO-AntivirusTrojan.Win32.TrjGen.csulmd
ViRobotTrojan.Win32.Agent.215901
SUPERAntiSpywareTrojan.Agent/Gen-Siggen
MicroWorld-eScanBackdoor.Zegost.BC
TencentMalware.Win32.Gencirc.10b406f5
Ad-AwareBackdoor.Zegost.BC
SophosML/PE-A + Troj/Zegost-CV
ComodoTrojWare.Win32.Kryptik.BPVQ@56xtf6
BitDefenderThetaGen:NN.ZexaF.34628.ni1@aOvpuhhb
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SML
McAfee-GW-EditionBackDoor-FCGT!6E674EAF23EB
FireEyeGeneric.mg.6e674eaf23eb868a
EmsisoftBackdoor.Zegost.BC (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.avrta
AviraBDS/Zegost.mdqcz
MicrosoftBackdoor:Win32/Zegost.AD
GridinsoftTrojan.Win32.Gen.vl!n
ArcabitBackdoor.Zegost.BC
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataBackdoor.Zegost.BC
TACHYONBackdoor/W32.Farfli.215909
AhnLab-V3Trojan/Win32.Scar.R65072
Acronissuspicious
McAfeeBackDoor-FCGT!6E674EAF23EB
MAXmalware (ai score=85)
VBA32BScope.Trojan.Dynamer
MalwarebytesBackdoor.Staser
PandaGeneric Malware
TrendMicro-HouseCallBKDR_ZEGOST.SML
RisingBackdoor.Farfli!1.B6C5 (RDMK:cmRtazqVD47XH1vts659jllJC9JK)
YandexTrojan.Kryptik!BskX9BEG55w
IkarusBackdoor.Win32.Zegost
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Farfli.PZ!tr
AVGWin32:Farfli-CF [Cryp]
Qihoo-360HEUR/QVM07.1.0030.Malware.Gen

How to remove Backdoor.Zegost.BC?

Backdoor.Zegost.BC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment