Backdoor

Backdoor:Win32/Zegost.X information

Malware Removal

The Backdoor:Win32/Zegost.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost.X virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial language used in binary resources: Spanish (Modern)

How to determine Backdoor:Win32/Zegost.X?


File Info:

crc32: 102CCF7E
md5: ae935f884666aa5a52e51708836fa198
name: AE935F884666AA5A52E51708836FA198.mlw
sha1: b5cc32a1e8dc869c5ac7a765eb459daefd135217
sha256: 2df9c981244da1efeb60198c90bcaab22f82b756e223f431a3f295b54ebc86cd
sha512: 8605c32dbe2db0b2612030c7dcb9d5d2fca82cbcfe03d5ef33f9c64c78b055de10dc8729aab1584bef27d0b177dbff370673700cf75dc7b408f48552abeffeb5
ssdeep: 6144:i5+Bs3D7ymY2cuH/pnIFepkpcfvXCfqqFMGC4uuuuuuuuuuuuuuuuuuuuuuuuuu:6Zvy0cWlpfvSfqqNuuuuuuuuuuuuuuu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Adobexae Flashxae Player. Copyright xa9 1996-2007 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327; Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
InternalName: Adobe Flash Player 9.0
FileVersion: 9,0,45,0
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe Flash Player
ProductName: Shockwave Flash
ProductVersion: 9,0,45,0
FileDescription: Adobe Flash Player 9.0 r45
OriginalFilename: SAFlashPlayer.exe
Debugger: 1
Translation: 0x0409 0x04b0

Backdoor:Win32/Zegost.X also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.DownLoader9.35319
MicroWorld-eScanTrojan.GenericKD.45650042
FireEyeGeneric.mg.ae935f884666aa5a
Qihoo-360Win32/Backdoor.e7f
McAfeeRDN/Generic BackDoor
MalwarebytesMalware.AI.4168004838
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusTrojan ( 004d03531 )
BitDefenderTrojan.GenericKD.45650042
K7GWTrojan ( 004d03531 )
Cybereasonmalicious.1e8dc8
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Fusing.BB
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Rincux-6417593-0
KasperskyBackdoor.Win32.Zegost.sym
AlibabaBackdoor:Win32/Zegost.7216bbc3
NANO-AntivirusTrojan.Win32.Zegost.cxbers
ViRobotTrojan.Win32.Z.Zegost.387996
TencentBackdoor.Win32.Zegost.f
Ad-AwareTrojan.GenericKD.45650042
SophosML/PE-A + Troj/Myrsky-A
ComodoMalware@#1q0rspun90x4p
F-SecureTrojan.TR/Crypt.ZPACK.Gen8
BaiduWin32.Trojan.Farfli.au
ZillyaBackdoor.Zegost.Win32.538
TrendMicroWORM_SDBOT.GEN-1
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftTrojan.GenericKD.45650042 (B)
IkarusBackdoor.Win32.Inject
JiangminHeur:Backdoor/Ghost
AviraTR/Crypt.ZPACK.Gen8
MAXmalware (ai score=84)
MicrosoftBackdoor:Win32/Zegost.X
ArcabitTrojan.Generic.D2B8907A
ZoneAlarmBackdoor.Win32.Zegost.sym
GDataTrojan.GenericKD.45650042
CynetMalicious (score: 85)
AhnLab-V3Backdoor/Win32.Zegost.R78441
VBA32Backdoor.Zegost
ALYacTrojan.GenericKD.45650042
TACHYONBackdoor/W32.Zegost.387996
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SDBOT.GEN-1
RisingBackdoor.Zegost!8.177 (TFE:5:KG9zzDzR8NS)
YandexTrojan.GenAsa!L2Rj8Kis+bM
FortinetW32/Farfli.GOST!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Zegost.X?

Backdoor:Win32/Zegost.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment