Backdoor

Backdoor:Win32/Zegost!pz removal instruction

Malware Removal

The Backdoor:Win32/Zegost!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Zegost!pz virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Zegost!pz?


File Info:

name: 0BC89E1EB8784CF4370D.mlw
path: /opt/CAPEv2/storage/binaries/f1688db4fc433b389d6eb10b260f51fe792b3a896b5952cbedb1e90eeb9787d5
crc32: DF4B2AA4
md5: 0bc89e1eb8784cf4370ddfa7d2b16ed6
sha1: 4cc476eac014f2ca5f4e748949f429f9fe65736d
sha256: f1688db4fc433b389d6eb10b260f51fe792b3a896b5952cbedb1e90eeb9787d5
sha512: a8b424154e686fbd5fb956612395a8dc5e180f5c5ff59a22d73fa75536622c91a9fade7938641cfec12bd8916e23343400b10d4d1ad8840dfbf9e0b17a32ea27
ssdeep: 3072:hhwVMQgpRh5qTsAyTDW2DQ80K7dPLjzNRwQR0ttTH1:o2Rnh5Esdm2E87RzYQR0j1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184146C22B5C644F7EE55153014EA2BBBA63DFA450B05AAC3771CCE691F33291A33724B
sha3_384: ac2b41d210986ad1b72cf526447389a7691c225e495fd5939da73c7bf1986f4dece2068d1463a24507fa9882cfc44742
ep_bytes: 558bec6aff68887242006808b8410064
timestamp: 2011-05-25 04:53:40

Version Info:

0: [No Data]

Backdoor:Win32/Zegost!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Genome.li3C
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Lime.3563
MicroWorld-eScanTrojan.GenericKDZ.103840
FireEyeGeneric.mg.0bc89e1eb8784cf4
CAT-QuickHealTrojan.Redosdru.K4
SkyhighGeneric BackDoor.dz
ALYacTrojan.GenericKDZ.103840
Cylanceunsafe
VIPRETrojan.GenericKDZ.103840
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Magania.299a8266
K7GWTrojan ( 00286dff1 )
K7AntiVirusTrojan ( 00286dff1 )
ArcabitTrojan.Generic.D195A0
BitDefenderThetaGen:NN.ZexaF.36744.mqW@aScmy3b
VirITTrojan.Win32.Agent3.PEX
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Farfli.FJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Gh0stRAT-6992317-0
KasperskyTrojan-GameThief.Win32.Magania.uaet
BitDefenderTrojan.GenericKDZ.103840
NANO-AntivirusTrojan.Win32.Lime.bemekh
AvastWin32:Agent-AQGZ [Trj]
TencentBackdoor.Win32.Gh0st.g
EmsisoftTrojan.GenericKDZ.103840 (B)
F-SecureBackdoor.BDS/Dedipros.AB
BaiduWin32.Trojan.Farfli.ai
ZillyaWorm.Palevo.Win32.124380
TrendMicroBKDR_TRATS.SMUJ
SophosMal/Redos-I
IkarusP2P-Worm.Win32.Palevo
JiangminTrojan/Generic.fwgf
WebrootW32.Malware.Gen
VaristW32/Palevo.I.gen!Eldorado
AviraBDS/Dedipros.AB
MAXmalware (ai score=100)
Antiy-AVLTrojan[GameThief]/Win32.Magania.uaet
Kingsoftmalware.kb.a.970
XcitiumTrojWare.Win32.Magania.~AAD@f80tc
MicrosoftBackdoor:Win32/Zegost!pz
ViRobotTrojan.Win32.A.Swisyn.212094
ZoneAlarmTrojan-GameThief.Win32.Magania.uaet
GDataWin32.Trojan.PSE.101MY6A
GoogleDetected
AhnLab-V3Worm/Win32.Palevo.C62163
Acronissuspicious
McAfeeGeneric BackDoor.dz
VBA32BScope.Trojan.Keylogger
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Swisyn.J
ZonerTrojan.Win32.24337
TrendMicro-HouseCallBKDR_TRATS.SMUJ
RisingBackdoor.Farfli!1.64D7 (CLASSIC)
YandexTrojan.Swisyn!uMu0elvfUuI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2413710.susgen
FortinetW32/Agent.D444!tr
AVGWin32:Agent-AQGZ [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Zegost!pz?

Backdoor:Win32/Zegost!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment