Backdoor

Should I remove “Backdoor:Win32/Zegost.B”?

Malware Removal

The Backdoor:Win32/Zegost.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

mfym.f3322.net

How to determine Backdoor:Win32/Zegost.B?


File Info:

crc32: 925E4192
md5: 62fead4039e0af1664a9473f4ad90e37
name: svchost.exe
sha1: 8f970a56c663dc5392783f2869902873bf6e47f2
sha256: a510fb988d873936d7c22ed69d79577353184cbb0f4f7ddb84c726b1a9dca39c
sha512: 00d39ce6d76d4c1f053cedda6b3c58300b92418cccb144db6a127e8c3eb4566f740f496e804a6b8f1b807ff9b1ede2478e6e5f2413fdf3fede723027e97c2c07
ssdeep: 3072:UuZxEE1Kiv7Q+x0pgrt1zFP9YDKAf0fMus9QBLqQIu/ypq9Spi6DJdh0AooKuopk:U2ciTQHa1zTYffN0BuQneq2Dh1ooKw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: adbrowser
FileVersion: 1, 0, 0, 9
CompanyName: Net.Soft Studio
PrivateBuild: 20120830.01
LegalTrademarks:
Comments:
ProductName: adbrowser
SpecialBuild:
ProductVersion: 1, 0, 0, 9
FileDescription: P2Px7ec8x7ed3x8005x8f85x52a9x6a21x5757
OriginalFilename: adbrowser.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.B also known as:

DrWebTrojan.Siggen6.56473
MicroWorld-eScanDeepScan:Generic.Rincux2.F61A2109
FireEyeGeneric.mg.62fead4039e0af16
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeBackDoor-FCGT!62FEAD4039E0
CylanceUnsafe
VIPREBackdoor.Win32.Zegost.add (v)
SangforMalware
K7AntiVirusTrojan ( 0040f7ad1 )
BitDefenderDeepScan:Generic.Rincux2.F61A2109
K7GWTrojan ( 0040f7ad1 )
Cybereasonmalicious.039e0a
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34090.mi1@aSNKpYbb
CyrenW32/Skintrim.1!Generic
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gh0stRAT-7474617-0
GDataDeepScan:Generic.Rincux2.F61A2109
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Zegost.37b02fdb
NANO-AntivirusTrojan.Win32.Zegost.cwfdlp
AegisLabTrojan.Win32.Glomaru.lXMS
TencentMalware.Win32.Gencirc.10b8afd8
Endgamemalicious (high confidence)
SophosTroj/Zegost-CV
ComodoBackdoor.Win32.Zegost.c@4m3x9i
F-SecureBackdoor.BDS/Zegost.Gen
ZillyaTrojan.Farfli.Win32.33917
TrendMicroBKDR_ZEGOST.SM04
McAfee-GW-EditionBehavesLike.Win32.HLLPPhilis.dc
Trapminemalicious.high.ml.score
EmsisoftDeepScan:Generic.Rincux2.F61A2109 (B)
IkarusTrojan.SuspectCRC
F-ProtW32/Skintrim.1!Generic
JiangminTrojan/Jorik.gkaj
WebrootW32.Trojan.Gen
AviraBDS/Zegost.Gen
MAXmalware (ai score=85)
ArcabitDeepScan:Generic.Rincux2.F61A2109
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.B
AhnLab-V3Trojan/Win32.Generic.R97658
Acronissuspicious
ALYacDeepScan:Generic.Rincux2.F61A2109
VBA32BScope.Backdoor.Zegost
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Farfli.ARD
TrendMicro-HouseCallBKDR_ZEGOST.SM04
RisingTrojan.Kryptik!1.AAD1 (CLOUD)
YandexTrojan.Agent!6gEY/46XybQ
SentinelOneDFI – Suspicious PE
FortinetW32/Farfli.PZA!tr
Ad-AwareDeepScan:Generic.Rincux2.F61A2109
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM07.1.8EAF.Malware.Gen

How to remove Backdoor:Win32/Zegost.B?

Backdoor:Win32/Zegost.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment