Malware

What is “Generic.Zegost.3.247D7862 (B)”?

Malware Removal

The Generic.Zegost.3.247D7862 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Zegost.3.247D7862 (B) virus can do?

  • At least one process apparently crashed during execution
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

1122.haoqing.me

How to determine Generic.Zegost.3.247D7862 (B)?


File Info:

crc32: F84C8150
md5: 92b9135780d6ecc14db2f5663418947e
name: 360.exe
sha1: 1cc52fa542fafd1448c1900c75adc52423d9e156
sha256: f92bd908be00c1f504e2e08dc7ab4f4a6fda15922fa017b9642ed49868653620
sha512: efd36c0eb14a4bfafc704b43c23494dd1f64855964a2cfb00243c11971011e7ffef0703c75e7738c617620324fef1a5a553a1de977c5b96de49af58a797bd552
ssdeep: 768:WyKaTvHdeECxsTt2znxwX0lEm9n4IEAdU85mCPlS8DXQ:dvHLCfzikYqU85x3Q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Microsoft Corp. All rights reserved.
InternalName: SQLBROWSER
FileVersion: 2011.0110.2100.060 ((SQL11_RTM).120210-1846 )
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks: Microsoft SQL Server is a registered trademark of Microsoft Corporation.
Comments: SQL
ProductName: Microsoft SQL Server
SpecialBuild:
ProductVersion: 11.0.2100.60
FileDescription: SQL Server Upgrade EXE
OriginalFilename: SQLUpgrade.EXE
Translation: 0x0804 0x04b0

Generic.Zegost.3.247D7862 (B) also known as:

MicroWorld-eScanGeneric.Zegost.3.247D7862
FireEyeGeneric.mg.92b9135780d6ecc1
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Zegost.3.247D7862
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.m64T
SangforMalware
K7AntiVirusTrojan ( 0053af701 )
BitDefenderGeneric.Zegost.3.247D7862
K7GWTrojan ( 0053af701 )
Cybereasonmalicious.780d6e
TrendMicroBKDR_BEAUGRIT.SM
BitDefenderThetaGen:Trojan.Heur.RP.dq0@aK0aYncb
F-ProtW32/KillAV.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
BaiduWin32.Trojan.Agent.atx
APEXMalicious
AvastWin32:Dropper-ODE [Drp]
ClamAVWin.Trojan.Generic-6305873-0
GDataGeneric.Zegost.3.247D7862
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Zegost.24abe6e7
NANO-AntivirusTrojan.Win32.Ric.fwtolq
ViRobotTrojan.Win32.Z.Agent.57344.JXU
RisingBackdoor.Farfli!1.64B3 (CLASSIC)
Ad-AwareGeneric.Zegost.3.247D7862
SophosMal/Generic-S
ComodoTrojWare.Win32.Fusing.CF@5afr59
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.DownLoader26.55235
ZillyaTrojan.Agent.Win32.1144030
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.qm
EmsisoftGeneric.Zegost.3.247D7862 (B)
SentinelOneDFI – Malicious PE
CyrenW32/KillAV.AU.gen!Eldorado
JiangminHeur:Backdoor/PcClient
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Zegost
Endgamemalicious (high confidence)
ArcabitGeneric.Zegost.3.247D7862
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.DA
AhnLab-V3Trojan/Win32.RL_Zegost.R294275
Acronissuspicious
McAfeeRDN/Generic BackDoor.ss
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.Agent.QQGen
PandaGeneric Malware
ESET-NOD32a variant of Win32/Agent.QID
TrendMicro-HouseCallBKDR_BEAUGRIT.SM
YandexTrojan.Agent!KO43df1nzLE
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Fusing.BB!tr
AVGWin32:Dropper-ODE [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM07.1.72D9.Malware.Gen

How to remove Generic.Zegost.3.247D7862 (B)?

Generic.Zegost.3.247D7862 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment