Backdoor

Backdoor:Win32/Zegost.BW information

Malware Removal

The Backdoor:Win32/Zegost.BW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.BW virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Zegost.BW?


File Info:

crc32: 45273C74
md5: 1dc59201d0ba0d570a4c4ee07584430d
name: good.exe
sha1: 3869860375558ecb17a4c0f18808754e48c84b59
sha256: 429d667df6244d45d6a58e8279a12d9bbbb81489a5c9767fa44ed3532491af86
sha512: c42d434ca6a5490d80f3a2154ea159f0f72bbef897311dce4ad045ec234cbac039c4e3831fed9d06300a0236e4ad8358c46683e2621c9312fca3d1c61ad67f4b
ssdeep: 3072:dR9cecthiLdNTWUShFq+VszA3nSoqIS0HLT5SatkCbe6vHDatkrtQ0FWQ:7ixbU4fq+VszKSNYrFdbe6vW2tQT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 360.cn All Rights Reserved.
InternalName: 360Login
FileVersion: 1, 0, 0, 1211
ProductName: 360x5b89x5168x536bx58eb
ProductVersion: 1, 0, 0, 1211
FileDescription: 360x5b89x5168x536bx58eb x5e10x6237x767bx9646x6a21x5757
OriginalFilename: WebLogin.exe
Translation: 0x0004 0x04b0

Backdoor:Win32/Zegost.BW also known as:

DrWebTrojan.DownLoader9.8143
MicroWorld-eScanGen:Variant.Graftor.145885
FireEyeGeneric.mg.1dc59201d0ba0d57
McAfeeArtemis!1DC59201D0BA
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0003ead81 )
BitDefenderGen:Variant.Graftor.145885
K7GWTrojan ( 0003ead81 )
Cybereasonmalicious.1d0ba0
TrendMicroCryp_Xin2
BitDefenderThetaGen:NN.ZexaF.34090.nu0@a8vZl8dj
F-ProtW32/Dropper.6!Generic
SymantecSMG.Heur!gen
TotalDefenseWin32/Zegost.UHOGJP
APEXMalicious
AvastWin32:Agent-BADD [Trj]
GDataGen:Variant.Graftor.145885
KasperskyTrojan-Dropper.Win32.Agent.oiap
AlibabaBackdoor:Win32/Zegost.2d2048c1
NANO-AntivirusTrojan.Win32.Magania.csluvs
AegisLabTrojan.Win32.Glomaru.mDOx
RisingBackdoor.Zegost!8.177 (RDMK:cmRtazpE7PkBHVOLv9ihnnIcrqJV)
Ad-AwareGen:Variant.Graftor.145885
EmsisoftGen:Variant.Graftor.145885 (B)
ComodoTrojWare.Win32.Farfli.BELT@5j3r14
F-SecureBackdoor.BDS/Zegost.Gen7
BaiduWin32.Trojan.Farfli.l
ZillyaTrojan.Magania.Win32.65153
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Malware.dh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Dropper.6!Generic
JiangminTrojan/PSW.Magania.bgyc
MaxSecureVirus.W32.Shodi.I
AviraBDS/Zegost.Gen7
Antiy-AVLTrojan[Dropper]/Win32.Agent.oiap
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.D239DD
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
ZoneAlarmTrojan-Dropper.Win32.Agent.oiap
MicrosoftBackdoor:Win32/Zegost.BW
TACHYONTrojan-PWS/W32.WebGame.214016.R
AhnLab-V3Trojan/Win32.Magania.R92960
Acronissuspicious
VBA32BScope.Trojan.SvcHorse.01643
ALYacGen:Variant.Graftor.145885
MAXmalware (ai score=85)
PandaTrj/Genetic.gen
ESET-NOD32Win32/Farfli.PZ
TrendMicro-HouseCallCryp_Xin2
TencentMalware.Win32.Gencirc.10b642ce
YandexTrojan.PWS.Magania!v+UH2KLH0GQ
IkarusVirus.Win32.PePatch
eGambitUnsafe.AI_Score_54%
FortinetW32/Magania.IQGR!tr
AVGWin32:Agent-BADD [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Backdoor.Win32.Gh0st.KD

How to remove Backdoor:Win32/Zegost.BW?

Backdoor:Win32/Zegost.BW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment