Backdoor

Backdoor:Win32/Zegost.CG removal

Malware Removal

The Backdoor:Win32/Zegost.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.CG virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
lisn11.f3322.net

How to determine Backdoor:Win32/Zegost.CG?


File Info:

crc32: F5335224
md5: c032d9ca8f07391c405379482014e634
name: svchost.exe
sha1: 7e9001003a6ca5172c8f73de595002f0dde3f080
sha256: 59bac54287250da5e9e549f1f71f88d7355b22a49e46806f4d3815dfbf3c359e
sha512: 2329469a7cb317356f03ab869dade4d5b9f3186c473645d0dec577c5874157de4c78cd74092c0fa7c37c27b6cce5755bce5370c386e9036b3045e8d0dadaaab1
ssdeep: 3072:TJP38g9ZRmqy3FOsraMNDvscOiF0IgH9DRJUyMiAG:T9PsdUiF0vH9FJ3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Zegost.CG also known as:

MicroWorld-eScanGen:Variant.Mikey.112225
FireEyeGeneric.mg.c032d9ca8f07391c
K7AntiVirusTrojan ( 004dc7d71 )
BitDefenderGen:Variant.Mikey.112225
K7GWTrojan ( 004dc7d71 )
TrendMicroBKDR_ZEGOST.SM19
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Gh0stRAT-7506001-1
GDataGen:Variant.Mikey.112225
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.hiyuby
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazq2OTpwxLUAnajPisB3xmN0)
Endgamemalicious (high confidence)
DrWebTrojan.Siggen6.56649
ZillyaTrojan.Kryptik.Win32.1971456
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Mikey.112225 (B)
IkarusBackdoor.Win32.Zegost
JiangminTrojan.Generic.cpufd
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.Zegost
MicrosoftBackdoor:Win32/Zegost.CG
ArcabitTrojan.Mikey.D1B661
ZoneAlarmHEUR:Trojan.Win32.Generic
BitDefenderThetaGen:NN.ZexaF.34106.mqW@a09yLWmb
ALYacGen:Variant.Mikey.112225
VBA32BScope.Trojan.DDoS.Nitol
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.EHHV
TrendMicro-HouseCallBKDR_ZEGOST.SM19
TencentMalware.Win32.Gencirc.10b9c4ce
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.EHHV!tr
Ad-AwareGen:Variant.Mikey.112225
AVGWin32:Trojan-gen
Cybereasonmalicious.a8f073
Qihoo-360Generic/Trojan.aac

How to remove Backdoor:Win32/Zegost.CG?

Backdoor:Win32/Zegost.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment