Trojan

TrojanDropper:Win32/Zegost.B removal guide

Malware Removal

The TrojanDropper:Win32/Zegost.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Zegost.B virus can do?

  • At least one process apparently crashed during execution
  • Presents an Authenticode digital signature
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDropper:Win32/Zegost.B?


File Info:

crc32: DB5881E2
md5: dda0d29ed1efd488df06c0cbda0101a7
name: server.exe
sha1: 9a29925b1ae4418ad38ceced4d28a70c8f985645
sha256: b91412cc299d8163eac9c4f7d9b987cbfb07e83e1842000d70a967a4a3d562a9
sha512: 2a02ed3dca65cc9310b4c5de268d2f5d3264069511638d2eae372a924253fbfc7bb3be48fe6bdc187e46166d93014e81212860fd1282cb2db469530a2b13029f
ssdeep: 6144:SsIZ6nW8QmBTyPRqyhYPbncTBlhHrindnkv0oX:/RW8uJq8YPbncT3p
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: SPUNINST.EXE
FileVersion: 6.3.0004.1 built by: dnsrv
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.3.0004.1
FileDescription: Windows Service Pack Uninstall
OriginalFilename: SPUNINST.EXE
Translation: 0x0804 0x04b0

TrojanDropper:Win32/Zegost.B also known as:

BkavW32.ZegostQKB.Trojan
ClamAVWin.Spyware.78740-1
FireEyeGeneric.mg.dda0d29ed1efd488
CAT-QuickHealTrojanDropper.Zegost.C5
McAfeeBackDoor-CEP.gen.cn
MalwarebytesTrojan.Dropper
SangforMalware
K7AntiVirusTrojan ( 0016e1f71 )
BitDefenderGen:Variant.Zegost.2
K7GWTrojan ( 0016e1f71 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BaiduWin32.Backdoor.Zegost.b
F-ProtW32/Zegost.C.gen!Eldorado
SymantecTrojan Horse
TotalDefenseWin32/Zegost.CJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
GDataGen:Variant.Zegost.2
KasperskyTrojan-PSW.Win32.Bjlog.dtwr
AlibabaTrojanPSW:Win32/Bjlog.d2e661aa
NANO-AntivirusTrojan.Win32.Bjlog.drshei
ViRobotTrojan.Win32.PSWBjlog.200704
AegisLabTrojan.Win32.Bjlog.lmoo
MicroWorld-eScanGen:Variant.Zegost.2
TencentBackdoor.Win32.Zegost.aaa
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zegost.2 (B)
ComodoBackdoor.Win32.Zegost.B@1qlsm2
F-SecureBackdoor:W32/Bjlog.D
DrWebBackDoor.Zegost.48
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_REDOS.SME
Trapminemalicious.high.ml.score
SophosMal/PWS-GA
SentinelOneDFI – Malicious PE
CyrenW32/Zegost.L.gen!Eldorado
JiangminTrojan/PSW.Bjlog.bvd
WebrootW32.Trojan.Gen
AviraTR/PSW.Bjlog.lfzb
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[PSW]/Win32.Bjlog.dtwr
MicrosoftTrojanDropper:Win32/Zegost.B
ArcabitTrojan.Zegost.2
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
ZoneAlarmTrojan-PSW.Win32.Bjlog.dtwr
AhnLab-V3Dropper/Zegost.206136
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Zegost.2
TACHYONTrojan-PWS/W32.Bjlog.209384
Ad-AwareGen:Variant.Zegost.2
ESET-NOD32a variant of Win32/Redosdru.FP
TrendMicro-HouseCallTROJ_REDOS.SME
RisingBackdoor.Win32.GenFxj.c (CLOUD)
YandexTrojan.Zegost.Gen.5
MAXmalware (ai score=81)
MaxSecureTrojan.Malware.6565302.susgen
FortinetW32/Bjlog.GL!tr
BitDefenderThetaAI:Packer.4D1960461F
AVGWin32:Zegost-C [Trj]
Cybereasonmalicious.ed1efd
PandaGeneric Malware
Qihoo-360Dropper.Win32.Zegost.A

How to remove TrojanDropper:Win32/Zegost.B?

TrojanDropper:Win32/Zegost.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment