Backdoor

Backdoor:Win32/Zegost.DS (file analysis)

Malware Removal

The Backdoor:Win32/Zegost.DS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.DS virus can do?

  • Unconventionial language used in binary resources: Chinese
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Zegost.DS?


File Info:

crc32: 7512B985
md5: 8dd24d3f90c0f76f6a2b2b23e8d38f0c
name: 8DD24D3F90C0F76F6A2B2B23E8D38F0C.mlw
sha1: bb7ef256a32775d1a2ab311dc2c34bde1b84f0a5
sha256: 601f96fffe11059d62e9b22b51d62b9b00678a2fd19b5c80052646ad28eb33df
sha512: 90229b17872d033ec640ee2af13de2d8d965011111950803f78008fd74b52e174f77c0b1a1fc2e1c6da3def2c4a17566e767f77388a7fed6828a3080f198e8fe
ssdeep: 1536:3yHWT1vMoZo9XMJTGgxJEtSAma3k/vXttcjUQiRN:3YcMiphPLNJXtDQi3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Zegost.DS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Farfli.1
FireEyeGeneric.mg.8dd24d3f90c0f76f
McAfeeArtemis!8DD24D3F90C0
CylanceUnsafe
VIPRETrojan.Win32.Redosdru.C (v)
AegisLabTrojan.Win32.Vehidis.4!c
SangforBackdoor.Win32.Farfli.1
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Farfli.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f90c0f
BitDefenderThetaGen:NN.ZexaF.34608.eyWbaCTyQQnO
CyrenW32/Symmi.AA.gen!Eldorado
SymantecRansom.Wannacry
TotalDefenseWin32/ASuspect.HAAOE
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Farfli-9758840-0
KasperskyTrojan.Win32.Vehidis.wp
AlibabaBackdoor:Win32/Vehidis.3c3f5ea1
NANO-AntivirusTrojan.Win32.KeyLogger.cuehck
RisingBackdoor.Farfli!1.A1B3 (CLOUD)
Ad-AwareGen:Variant.Farfli.1
SophosML/PE-A + Troj/HkMain-CB
ComodoTrojWare.Win32.Ransom.PornoAsset.ZUS@54n8s8
F-SecureHeuristic.HEUR/AGEN.1107555
DrWebTrojan.KeyLogger.23402
ZillyaTrojan.Farfli.Win32.16441
McAfee-GW-EditionBehavesLike.Win32.Dropper.lc
EmsisoftGen:Variant.Farfli.1 (B)
AviraHEUR/AGEN.1107555
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Zegost.DS
ArcabitTrojan.Farfli.1
ZoneAlarmTrojan.Win32.Vehidis.wp
GDataGen:Variant.Farfli.1
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Farfli.AIY
VBA32TrojanPSW.Magania
ALYacGen:Variant.Farfli.1
MalwarebytesMalware.Heuristic.1004
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM26
TencentWin32.Trojan.Vehidis.Efla
YandexTrojan.Farfli!gh7wkJ4bhVc
IkarusTrojan-Downloader
FortinetW32/Vehidis.U!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Zegost.Hw0AEpsA

How to remove Backdoor:Win32/Zegost.DS?

Backdoor:Win32/Zegost.DS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment