Malware

Should I remove “Generic.ZegostS.B3ADE1B1”?

Malware Removal

The Generic.ZegostS.B3ADE1B1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ZegostS.B3ADE1B1 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

www.sock8.com

How to determine Generic.ZegostS.B3ADE1B1?


File Info:

crc32: 49AA0F3C
md5: 0190e600e846bb0ab7a12e6f431c669a
name: server.exe
sha1: a02123ccb9d00a7950bc7b4d50c781b779df0cd3
sha256: 4b510cb531778c51f99032e0d52ef65f5372cd08298fefc5a415b5270d82a15b
sha512: a733be0566e018c5f447315d61ebe869c37e617c60d30dcba987a0c23e3cf5426649583168fb3fbf6a5bb0ee13c8af1ca27dbf6c0b5f862f24ef59ccb325f5cf
ssdeep: 6144:kiT6bWB0sL7tSJ5pp34OplSL4G7v4G7AWFQbf:TVB0sdSrpNty9JAl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.ZegostS.B3ADE1B1 also known as:

BkavW32.BallerFamKA.Worm
MicroWorld-eScanGeneric.ZegostS.B3ADE1B1
FireEyeGeneric.mg.0190e600e846bb0a
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Backdoor.Win32.Gh0st.DC
McAfeeBackDoor-DVB.gen.a
CylanceUnsafe
VIPRETrojan.Win32.Generic!SB.0
SangforMalware
K7AntiVirusP2PWorm ( 00254e991 )
BitDefenderGeneric.ZegostS.B3ADE1B1
K7GWP2PWorm ( 00254e991 )
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
BaiduWin32.Trojan.Farfli.ai
F-ProtW32/Palevo.I.gen!Eldorado
SymantecBackdoor.Trojan
TotalDefenseWin32/Gosht.AY
APEXMalicious
AvastWin32:Agent-AMXK [Trj]
ClamAVWin.Trojan.Magania-6971504-0
GDataGeneric.ZegostS.B3ADE1B1
KasperskyP2P-Worm.Win32.Palevo.iejc
NANO-AntivirusTrojan.Win32.Keylog.cqolzo
ViRobotWorm.Win32.A.P2P-Palevo.336058.J
RisingBackdoor.Farfli!1.64D7 (RDMK:cmRtazoDnDJ/pWDM2/X9nk3QuddE)
Endgamemalicious (high confidence)
EmsisoftGeneric.ZegostS.B3ADE1B1 (B)
ComodoTrojWare.Win32.Magania.~AAD@f80tc
F-SecureBackdoor.BDS/Zegost.adouma
DrWebTrojan.Keylog.507
ZillyaWorm.Palevo.Win32.64763
TrendMicroTROJ_PALEVO.SMUM
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
SophosMal/Redos-I
IkarusP2P-Worm.Win32.Palevo
CyrenW32/Palevo.I.gen!Eldorado
JiangminTrojan/Generic.fgzt
WebrootW32.Worm.Palevo
AviraBDS/Zegost.adouma
MAXmalware (ai score=80)
ArcabitGeneric.ZegostS.B3ADE1B1
SUPERAntiSpywareTrojan.Agent/Gen-Palevo
ZoneAlarmP2P-Worm.Win32.Palevo.iejc
MicrosoftBackdoor:Win32/Zegost.AD
AhnLab-V3Win-Trojan/Palevo.Gen
Acronissuspicious
VBA32BScope.Trojan.Keylogger
ALYacGeneric.ZegostS.B3ADE1B1
Ad-AwareGeneric.ZegostS.B3ADE1B1
PandaTrj/Genetic.gen
ZonerTrojan.Win32.31202
ESET-NOD32a variant of Win32/Farfli.RG
TrendMicro-HouseCallTROJ_PALEVO.SMUM
TencentBackdoor.Win32.Gh0st.g
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetW32/KeyLogger.514D!tr
BitDefenderThetaGen:NN.ZexaF.34100.uqX@a0@v0wgj
AVGWin32:Agent-AMXK [Trj]
Cybereasonmalicious.0e846b
MaxSecureWorm.Palevo.cqmm

How to remove Generic.ZegostS.B3ADE1B1?

Generic.ZegostS.B3ADE1B1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment