Backdoor

Backdoor:Win32/Zegost.AY removal tips

Malware Removal

The Backdoor:Win32/Zegost.AY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.AY virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Zegost.AY?


File Info:

name: AD2AB32FC812EA1F21C7.mlw
path: /opt/CAPEv2/storage/binaries/dd080822b7f3a6f026c9829ea5f5b36b32991cebe2dc4dc71616f7c4fe714e12
crc32: 26594AB6
md5: ad2ab32fc812ea1f21c7715a4baa5b6b
sha1: bafb4212f46be0e7d709b39c4f14b8072634ed43
sha256: dd080822b7f3a6f026c9829ea5f5b36b32991cebe2dc4dc71616f7c4fe714e12
sha512: 46ac8e08c69ff366349e10528dd7b9994a15ab0d789b3019d563a342cabb444384247fe971eb72451853a4aae17dd18ebef37f621afaabf3f79da8cb2e6eb7c5
ssdeep: 6144:oSg07M0asdqvDNXX+Ws8xbvTnr5qPLgxq:oSg6aDpXU8xLTr5qPLj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148249E04617226FAF47BC0F29EA6E17956585C505B80588BFFF72E1F2AA50C136B3387
sha3_384: e4b60739d13399cdce9b3637a175f7c7334d5eb2b8ba821c975d044c4b1d8127fdadeb44ed6d5295767a6b507fcd5233
ep_bytes: 558bec6aff6860dc40006848c6400064
timestamp: 2014-09-17 17:14:52

Version Info:

0: [No Data]

Backdoor:Win32/Zegost.AY also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.mxIB
MicroWorld-eScanGen:Variant.Barys.54498
FireEyeGeneric.mg.ad2ab32fc812ea1f
CAT-QuickHealBackdoor.Zegost
ALYacGen:Variant.Barys.54498
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.54498
SangforSuspicious.Win32.Save.ins
AlibabaWorm:Win32/Palevo.79ab7d63
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36318.niW@a4t9irgb
CyrenW32/ABRisk.HOMC-1623
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.BGTP
APEXMalicious
KasperskyP2P-Worm.Win32.Palevo.ijre
BitDefenderGen:Variant.Barys.54498
NANO-AntivirusTrojan.Win32.Palevo.dfodal
ViRobotTrojan.Win32.U.Agent.114504
AvastWin32:Nitol-B [Trj]
TencentMalware.Win32.Gencirc.13eb0385
EmsisoftGen:Variant.Barys.54498 (B)
BaiduWin32.Trojan.Farfli.bs
F-SecureBackdoor.BDS/Zegost.klzeime
DrWebTrojan.DownLoader11.34178
TrendMicroTROJ_GEN.R002C0DGR23
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.54498
JiangminWorm/Palevo.dhns
GoogleDetected
AviraBDS/Zegost.klzeime
MAXmalware (ai score=83)
Antiy-AVLWorm[P2P]/Win32.Palevo
XcitiumWorm.Win32.Palevo.DH@5t6uvz
ArcabitTrojan.Barys.DD4E2
ZoneAlarmP2P-Worm.Win32.Palevo.ijre
MicrosoftBackdoor:Win32/Zegost.AY
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hupe.Gen
McAfeeArtemis!AD2AB32FC812
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGR23
RisingBackdoor.Farfli!1.65C0 (CLASSIC)
YandexWorm.P2P.Palevo!9kTD24hzxdM
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Dropper.PALV!tr
AVGWin32:Nitol-B [Trj]
Cybereasonmalicious.fc812e
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Zegost.AY?

Backdoor:Win32/Zegost.AY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment