Backdoor

Backdoor:Win32/Zegost.L removal guide

Malware Removal

The Backdoor:Win32/Zegost.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.L virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • Starts servers listening on 0.0.0.0:26571
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

Related domains:

edns.duckdns.org

How to determine Backdoor:Win32/Zegost.L?


File Info:

crc32: DF46BFEE
md5: 3869c43bea2e3de41971f22e10182fb2
name: 64ja.exe
sha1: 5209ece6f4a6ca119c94ef040a2007a12a881b2d
sha256: 3d8b9caf9c4c837701eb2f92d103c15936d96e47ea0eae7a0d6aad0067d41d35
sha512: dba3115c06e515788f04f5f5bc044a31f666e97f6753da12183e82518fed2f99a826cd4ff364a6ff8f6bed054257448b6fd22a978eb88394829f8365ddedf6dc
ssdeep: 98304:i2YsWcaRNzMJl7x4WU+e0g8yrLwLmgIn9Ab55:p/u+34ttBwLPu6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 5.9.4.10795
ProductVersion: 5.9
Translation: 0x0804 0x04b0

Backdoor:Win32/Zegost.L also known as:

DrWebBackDoor.PcClient.6599
MicroWorld-eScanTrojan.GenericKD.42253209
FireEyeGeneric.mg.3869c43bea2e3de4
CAT-QuickHealTrojan.Mauvaise.S1125931
Qihoo-360Win32/Trojan.ae7
ALYacTrojan.GenericKD.42253209
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005104ad1 )
BitDefenderTrojan.GenericKD.42253209
K7GWTrojan ( 005104ad1 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroBKDR_ZEGOST.SM45
BitDefenderThetaGen:NN.ZexaF.34090.pi0faqO9XDhi
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Pcclient-6959093-0
GDataTrojan.GenericKD.42253209
KasperskyTrojan-GameThief.Win32.Magania.uglq
NANO-AntivirusTrojan.Win32.Agent.erpjbl
RisingTrojan.ShadowBrokers!8.B976 (CLOUD)
Ad-AwareTrojan.GenericKD.42253209
SophosMal/Generic-S
F-SecureExploit.EXP/Agent.asbdu
ZillyaTrojan.GenericKD.Win32.62840
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42253209 (B)
IkarusBackdoor.Pcclient
CyrenW32/Trojan.CTWK-5954
JiangminTrojan.Imeternal.d
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1036226
MAXmalware (ai score=84)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D284BB99
ZoneAlarmTrojan-GameThief.Win32.Magania.uglq
MicrosoftBackdoor:Win32/Zegost.L
Acronissuspicious
McAfeeArtemis!3869C43BEA2E
VBA32TrojanDropper.Agent
MalwarebytesPUP.Optional.ChinAd
ZonerTrojan.Win32.64540
ESET-NOD32Win32/Farfli.CJT
TrendMicro-HouseCallBKDR_ZEGOST.SM45
TencentWin32.Trojan-gamethief.Magania.Lkeb
YandexTrojan.DR.Agent!ivI7Xr566q8
SentinelOneDFI – Suspicious
eGambitUnsafe.AI_Score_94%
FortinetW32/ZEGOST.SM45!tr.bdr
AVGWin32:Malware-gen
Cybereasonmalicious.bea2e3
PandaTrj/Genetic.gen
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Backdoor:Win32/Zegost.L?

Backdoor:Win32/Zegost.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment