Malware

Troj/Zegost-Q removal guide

Malware Removal

The Troj/Zegost-Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Zegost-Q virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Zegost-Q?


File Info:

name: AB994F736B677A5F3E16.mlw
path: /opt/CAPEv2/storage/binaries/1d7125b562f0d85227c0d8d081da5b5c6a9c2e4996ddf9fd9e041650f3dd0877
crc32: DFA362FB
md5: ab994f736b677a5f3e168fb77d536613
sha1: 5613cf5c96896f8cad3d19d03cc3b57287135824
sha256: 1d7125b562f0d85227c0d8d081da5b5c6a9c2e4996ddf9fd9e041650f3dd0877
sha512: aae4d6574d8b27456e382397cff1fadbf5150f71c957ad04fb48f784b88e717c5c34d2b3a999f5afd9a93ad65922e718af0a6d8568b3e3a1d404ba83227a0e58
ssdeep: 12288:AM5HHC52oxL3aKHx5r+TuxPhNWwgsAO3otV+:AM5HHC0w3aKHx5r+TuxPhpgpOmV+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAB45B83D6BF44E6C4EC0435D6B9D2B6FA70DEC17586CE166B90E913D6B63112E2033A
sha3_384: d485601a7779e950a5626edb2c7995d6fa719591d5894d033f30423a7ff584a614e49adfbafbc59a0d6063476a5883ae
ep_bytes: 558bec6aff688800480068f2a44e0064
timestamp: 2011-09-17 08:05:45

Version Info:

0: [No Data]

Troj/Zegost-Q also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lEQX
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34435242
ClamAVWin.Trojan.Zegost-9806367-0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeBackDoor-EMA.gen.i
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.34435242
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e3e41 )
AlibabaMalware:Win32/km_2cfce.None
K7GWTrojan ( 0055e3e41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D20D70AA
BaiduWin32.Trojan.Farfli.z
VirITBackdoor.Win32.Agent.ANJS
CyrenW32/Zegost.Z.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.ARB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ojzh
BitDefenderTrojan.GenericKD.34435242
NANO-AntivirusTrojan.Win32.Zegost.ctmrek
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
AvastWin32:Farfli-AV [Trj]
TencentMalware.Win32.Gencirc.10b2f993
EmsisoftTrojan.GenericKD.34435242 (B)
F-SecureBackdoor.BDS/Zegost.lmuna
DrWebTrojan.DownLoader4.63377
ZillyaTrojan.Jorik.Win32.39410
TrendMicroBKDR_ZEGOST.SM44
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ab994f736b677a5f
SophosTroj/Zegost-Q
IkarusBackdoor.Win32.Zegost
JiangminTrojan/Generic.mcku
WebrootW32.Malware.Gen
AviraBDS/Zegost.lmuna
Antiy-AVLTrojan/Win32.Zegost
XcitiumBackdoor.Win32.Agent.FDN@4ma6bj
MicrosoftBackdoor:Win32/Zegost.AD
ViRobotTrojan.Win.Z.Zegost.534145
ZoneAlarmTrojan.Win32.Scar.ojzh
GDataWin32.Trojan.PSE.112CPSD
GoogleDetected
AhnLab-V3Trojan/Win32.Bjlog.R11787
BitDefenderThetaGen:NN.ZexaF.36318.GuY@aaokhVfb
ALYacTrojan.GenericKD.34435242
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM44
RisingBackdoor.Farfli!1.64D7 (CLASSIC)
YandexTrojan.Farfli!b+y/LdufysI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Farfli.FX!tr
AVGWin32:Farfli-AV [Trj]
Cybereasonmalicious.36b677
DeepInstinctMALICIOUS

How to remove Troj/Zegost-Q?

Troj/Zegost-Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment