Backdoor

How to remove “Backdoor:Win32/Zegost.DF!bit”?

Malware Removal

The Backdoor:Win32/Zegost.DF!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.DF!bit virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

Related domains:

tta.monerorx.com
dns.monerogb.com

How to determine Backdoor:Win32/Zegost.DF!bit?


File Info:

crc32: 1CC94970
md5: beaa20f7cc0f9d7ec5d522c0faa96929
name: BEAA20F7CC0F9D7EC5D522C0FAA96929.mlw
sha1: e211cca58044b0788f68b32503ac9390a518379d
sha256: b6a56587ff63ad2c27323d56510915125be1f171324029353303659eb438d0ed
sha512: 6bc1d28b60c742c89a27ab755aa9ee680e437bd3bbc148ae76c2906281d511ee6a786bac2664e0c5ece396f42d001342801724a2ab3efb4ed4bf2e3600387aca
ssdeep: 12288:XSyDnzSsi1GVTksAE17gAIVLopKZA3rDAN23/NTsWOd7tE:XzDn2L1ATktk7HIqpKZAbDAN23/WL5a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: csfe
FileVersion: 1.0.0.0
CompanyName: csfe
Comments: ddd
ProductName: dd
ProductVersion: 1.0.0.0
FileDescription: ddd
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.DF!bit also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.310180
FireEyeGeneric.mg.beaa20f7cc0f9d7e
CAT-QuickHealBackdoor.Generic
ALYacGen:Variant.Zusy.310180
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.lwoF
SangforWin.Malware.Zusy-6840460-0
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Zusy.310180
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.7cc0f9
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Zusy-6840460-0
KasperskyHEUR:Backdoor.Win32.Generic
AlibabaBackdoor:Win32/Generic.c3fc12cd
NANO-AntivirusTrojan.Win32.Sdbot.ihkedy
ViRobotTrojan.Win32.Z.Zusy.966656.X
TencentWin32.Trojan-gamethief.Magania.Pjnm
Ad-AwareGen:Variant.Zusy.310180
EmsisoftGen:Variant.Zusy.310180 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan.TR/AD.ZombieBoy.bzuyh
DrWebBackDoor.IRC.Sdbot.34272
TrendMicroBackdoor.Win32.ZEGOST.THBOCBA
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Disabler
JiangminTrojan.Kolovorot.dhc
WebrootW32.Trojan.Gen
AviraTR/AD.ZombieBoy.bzuyh
Antiy-AVLGrayWare/Win32.FlyStudio.a
KingsoftWin32.Heur.KVM005.a.(kcloud)
MicrosoftBackdoor:Win32/Zegost.DF!bit
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Zusy.D4BBA4
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Zusy.310180
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_CoinMiner.R352671
Acronissuspicious
McAfeeGenericRXEN-RQ!BEAA20F7CC0F
MAXmalware (ai score=89)
VBA32TrojanPSW.Magania
MalwarebytesAdware.ChinAd
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.THBOCBA
RisingBackdoor.Generic!8.CE (TFE:5:ShAkuGqKOzI)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34804.7q0@a04dABpb
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.d55

How to remove Backdoor:Win32/Zegost.DF!bit?

Backdoor:Win32/Zegost.DF!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment