Backdoor

Backdoor:Win32/Zegost.CD!bit removal guide

Malware Removal

The Backdoor:Win32/Zegost.CD!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.CD!bit virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

t.nxxxn.ga

How to determine Backdoor:Win32/Zegost.CD!bit?


File Info:

crc32: 7172A680
md5: e922d581d4ec1f4fbea9dd6a2e29088a
name: SQLIOMDSD.exe
sha1: cd2fd300cb5f5d8c0410fdd833a4723145d2ca79
sha256: 5ab627f3c358738d60d0798b05e8e275958dd0058eb8fee2ec4ad360083984f6
sha512: 9265490318c57fa4acf1c1a3fbcedd16a7e0aea11e5c4dc3682fd1e74059a8cccab544259e683ee3bf1f99a9795423f02d705b2a62c3a007d61ea23032f13a5e
ssdeep: 384:B/dxXkROvwuK76kNQexc+v2PVGsa1IJyGxsTKV9K2fId1F7vvxlLYe:B/v0wWzHc+v2Pssa1pGyTdF7Db
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
InternalName: 360DnsOpt
FileVersion: 1.0.0.1058
CompanyName: 360x4e92x8054x7f51x5b89x5168x4e2dx5fc3
ProductName: 360x5b89x5168x536bx58eb
ProductVersion: 1.0.0.1058
FileDescription: 360x5b89x5168x536bx58eb DNSx4f18x9009
OriginalFilename: 360DnsOpt.exe
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.CD!bit also known as:

MicroWorld-eScanGenPack:Generic.Zegost.3.E594680F
FireEyeGeneric.mg.e922d581d4ec1f4f
CAT-QuickHealTrojan.GenericPMF.S7517963
Qihoo-360HEUR/QVM18.1.1F71.Malware.Gen
McAfeeTrojan-INV
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1126264
SangforMalware
K7AntiVirusTrojan ( 004d57481 )
BitDefenderGenPack:Generic.Zegost.3.E594680F
K7GWTrojan ( 004d57481 )
Cybereasonmalicious.1d4ec1
Invinceaheuristic
BitDefenderThetaAI:Packer.6D0060711F
F-ProtW32/Farfli.BA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.QJH
BaiduWin32.Trojan.Agent.atj
TrendMicro-HouseCallBKDR_ZEGOST.SM40
AvastWin32:Dropper-ODE [Drp]
ClamAVWin.Malware.Zegost-6919579-0
GDataGenPack:Generic.Zegost.3.E594680F
KasperskyHEUR:Trojan.Win32.Generic
RisingBackdoor.Farfli!8.B4 (TFE:5:4kN3d1oYb6H)
Ad-AwareGenPack:Generic.Zegost.3.E594680F
SophosMal/Behav-024
ComodoTrojWare.Win32.PSW.GamePass.F@35ift2
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Spy.2436
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM40
McAfee-GW-EditionBehavesLike.Win32.Mydoom.mc
SentinelOneDFI – Malicious PE
CMCVirus.Win32.Sality!O
EmsisoftGenPack:Generic.Zegost.3.E594680F (B)
APEXMalicious
CyrenW32/Farfli.BA.gen!Eldorado
JiangminTrojan/Generic.bcjgw
WebrootW32.Malware.Mlpe
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Zegost
Endgamemalicious (high confidence)
ArcabitGenPack:Generic.Zegost.3.E594680F
AhnLab-V3Backdoor/Win32.RL_Zegost.R289802
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.CD!bit
TACHYONBackdoor/W32.Farfli.22528.B
Acronissuspicious
VBA32BScope.Trojan.Agent
ALYacGenPack:Generic.Zegost.3.E594680F
MAXmalware (ai score=88)
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ZonerTrojan.Win32.68809
TencentMalware.Win32.Gencirc.10b0c2af
YandexBackdoor.Farfli!S9/WFy1iLOU
IkarusTrojan.Win32.Agent
FortinetW32/Agent.QJH!tr
AVGWin32:Dropper-ODE [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Backdoor:Win32/Zegost.CD!bit?

Backdoor:Win32/Zegost.CD!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment