Backdoor

Backdoor:Win32/Zegost.CC removal tips

Malware Removal

The Backdoor:Win32/Zegost.CC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.CC virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Zegost.CC?


File Info:

name: 89B1832DEA411D486177.mlw
path: /opt/CAPEv2/storage/binaries/3077e0480669f6fbb1b29188f0b4a5450f96229080de29a55f9f79292429f41e
crc32: 59FD7D52
md5: 89b1832dea411d486177e1654b68bdab
sha1: 4fdd696d9551c44ec3deca1f2dcccb2a32d7a36b
sha256: 3077e0480669f6fbb1b29188f0b4a5450f96229080de29a55f9f79292429f41e
sha512: ae15e5fd50fe283b9a0a54c61dddb39ebadd73196bb89f9dcf95d21e963ae5cf3335caa8067ae2287c7f88e4d62f57d0e0ef616476c993f4812299ebdf68a505
ssdeep: 3072:CXqf8CMQpYvJ/Op/6DCYvaGeO67lhcp5zaQu4EO414auRa7ehdfyrZr89Kpy7E3S:CXs8hQCB/YIC2SO67l+zaffuRkehByFI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9F3BF02FA4540FED294057C58FA777AE63B7CA5AA18EF837314FE550C72091AB32297
sha3_384: 85f2fbfd382dadc70707936887832fcb3d382895f39ad92e6ff34695c5ec063612bdd3e0142b79047ddce6790aab3a8f
ep_bytes: 558bec6aff68f8134000687023400064
timestamp: 2009-05-18 01:37:35

Version Info:

Comments:
CompanyName: 360安全中心
FileDescription: 360安全卫士签名验证模块
FileVersion: 0, 0, 0, 0
InternalName: 360Verify
LegalCopyright: Copyright (C) 2006-2008 360.cn
LegalTrademarks:
OriginalFilename: 360Verify.dll
PrivateBuild:
ProductName: 360安全卫士签名验证模块
ProductVersion: 1, 0, 0, 1001
SpecialBuild:
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.CC also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lCR2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Doina.10498
FireEyeGeneric.mg.89b1832dea411d48
CAT-QuickHealTrojan.Aksula.A
SkyhighBackDoor-DZB
ALYacGen:Variant.Application.Doina.10498
MalwarebytesGeneric.Trojan.Dialer.DDS
VIPREGen:Variant.Application.Doina.10498
SangforSuspicious.Win32.Save.ins
K7AntiVirusDialer ( 0009ea801 )
BitDefenderGen:Variant.Application.Doina.10498
K7GWDialer ( 0009ea801 )
Cybereasonmalicious.d9551c
ArcabitTrojan.Application.Doina.D2902
BitDefenderThetaAI:Packer.98F21B151F
VirITBackdoor.Win32.Agent.AFLK
SymantecTrojan.Dropper
ESET-NOD32Win32/Dialer.NHO
APEXMalicious
ClamAVWin.Trojan.Zegost-9760656-0
KasperskyBackdoor.Win32.Agent.alqt
AlibabaMalware:Win32/km_26ae.None
NANO-AntivirusTrojan.Win32.Pigeon.irbpno
ViRobotBackdoor.Win32.Agent.13312.L
RisingTrojan.Agent!1.650A (CLASSIC)
SophosML/PE-A
BaiduWin32.Trojan.Dialer.p
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Pigeon.22385
ZillyaBackdoor.Agent.Win32.155
TrendMicroBKDR_AGENT.SMZQ
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Application.Doina.10498 (B)
IkarusTrojan-Dropper.Agent
JiangminBackdoor/Agent.bsix
WebrootW32.Backdoor.Gen
GoogleDetected
AviraTR/Spy.Gen
VaristW32/Backdoor.TWTK-0450
Antiy-AVLTrojan[Backdoor]/Win32.FirstInj
KingsoftWin32.HeurC.KVM005.a
XcitiumTrojWare.Win32.Magania.~all@f80ty
MicrosoftBackdoor:Win32/Zegost.CC
ZoneAlarmBackdoor.Win32.Agent.alqt
GDataGen:Variant.Application.Doina.10498
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Magania.R6245
McAfeeBackDoor-DZB
DeepInstinctMALICIOUS
VBA32BScope.Trojan.SvcHorse.01643
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallBKDR_AGENT.SMZQ
TencentTrojan.Win32.Zeogst.ab
YandexTrojan.GenAsa!TwT3bfT3kGM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dialer.NEW
AVGWin32:Agent-AGNT [Drp]
AvastWin32:Agent-AGNT [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Zegost.CC?

Backdoor:Win32/Zegost.CC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment