Backdoor

What is “Backdoor:Win32/Zegost.CI!bit”?

Malware Removal

The Backdoor:Win32/Zegost.CI!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.CI!bit virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
dawnmining.top

How to determine Backdoor:Win32/Zegost.CI!bit?


File Info:

crc32: DACF2ED7
md5: 39bbc027407514ff28673ff9b306c2ca
name: 39BBC027407514FF28673FF9B306C2CA.mlw
sha1: bf8160d53c234b0c3c2a4d87ba2a9dd803c603d8
sha256: 5e1a8e79e03802f0141512882f5d17ae26146448b9933050de1bb13ecb2bb212
sha512: df7a0864876f8b9da40a89e2c6e8209879b2295c72b9907ebe3a03c88f3beca0b2f5d819440eb1314554299c869d5ed074134288465ba984431705e100c6f2e9
ssdeep: 6144:rR4RsEZtGzlYIVsWH5I716peaxnNZuuN:rR4SEjG5/3H5TpeEnH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2006
InternalName: Sinusoid
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Sinusoid x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Sinusoid Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Sinusoid.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.CI!bit also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.39bbc027407514ff
ALYacGen:Trojan.Malware.uq0@a47Ib4bb
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00521b151 )
BitDefenderGen:Trojan.Malware.uq0@a47Ib4bb
K7GWTrojan ( 00521b151 )
Cybereasonmalicious.740751
CyrenW32/Kryptik.BWY.gen!Eldorado
SymantecBackdoor.Zegost
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 85)
KasperskyHEUR:Trojan-Downloader.Win32.Generic
NANO-AntivirusTrojan.Win32.Zegost.erpbsz
AegisLabTrojan.Win32.Generic.a!c
MicroWorld-eScanGen:Trojan.Malware.uq0@a47Ib4bb
Ad-AwareGen:Trojan.Malware.uq0@a47Ib4bb
EmsisoftGen:Trojan.Malware.uq0@a47Ib4bb (B)
ComodoBackdoor.Win32.Farfli.FHH@7ok41s
F-SecureHeuristic.HEUR/AGEN.1131541
DrWebTrojan.DownLoader25.16839
ZillyaTrojan.Kryptik.Win32.1239574
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionPacked-MW!39BBC0274075
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1131541
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Zegost.CI!bit
ArcabitTrojan.Malware.E59FC7
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataGen:Trojan.Malware.uq0@a47Ib4bb
AhnLab-V3Malware/Win32.Generic.C2065505
McAfeePacked-MW!39BBC0274075
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesMalware.AI.4078967579
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FHSE
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingTrojan.Kryptik!1.AAD1 (CLASSIC)
YandexTrojan.GenAsa!CyO9JOL4i60
IkarusTrojan.Win32.Crypt
FortinetW32/Filecoder.FV!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34804.uq0@a47Ib4bb
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Zegost.HgIASOMA

How to remove Backdoor:Win32/Zegost.CI!bit?

Backdoor:Win32/Zegost.CI!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment