Trojan

Trojan:Win32/Zegost.CJ!bit removal

Malware Removal

The Trojan:Win32/Zegost.CJ!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zegost.CJ!bit virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

How to determine Trojan:Win32/Zegost.CJ!bit?


File Info:

crc32: 16D3CFA6
md5: 0829cd88fd7c3b0a7209107e71a0aff5
name: win-x.exe
sha1: eb1c3d9b1ecc312bdc560ebe083525e3219849e9
sha256: a2ab122994f580e4e5587912dfcfcce4c552219711ac6882b9e00c60245521ad
sha512: 5d78bb123f671f62552f3d2306579ab6d1192d33755d03fb82b1fae9ad98a5aed237d24e870ccd72bea9c601cd0e1ff7e6ffcdc7cb0e3e858bd431e29faf8b01
ssdeep: 24576:w/ZjoproKoZv4CDpqnGYmTOAD8hDaeE+rJSvHyMq2r5Z81IJO:0ZcW48YmTHD8hee/rJSvHfG1IJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2012
InternalName: BIGMsgr
FileVersion: 3,2,0,316
CompanyName: MSN China
ProductName: Windows Live Messenger x52a0x5f3ax7248x5b89x88c5x7a0bx5e8f
ProductVersion: 3,2,0,316
FileDescription: Install_WLMessenger
OriginalFilename: Install_WLMessenger.exe
Translation: 0x0804 0x04b0

Trojan:Win32/Zegost.CJ!bit also known as:

DrWebTrojan.Damaged.1
MicroWorld-eScanGen:Variant.Graftor.464791
FireEyeGeneric.mg.0829cd88fd7c3b0a
CAT-QuickHealBackdoor.Farfli
Qihoo-360Win32/Backdoor.7a0
McAfeePacked-MW!0829CD88FD7C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Farfli.m!c
K7AntiVirusTrojan ( 004fbf8e1 )
BitDefenderGen:Variant.Graftor.464791
K7GWTrojan ( 004fbf8e1 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroBKDR_ZEGOST.SM34
BitDefenderThetaGen:NN.ZexaF.34090.rs0@a0jAyXgj
CyrenW32/Trojan.TAAX-5969
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FHSE
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.464791
KasperskyBackdoor.Win32.Farfli.bpoz
AlibabaBackdoor:Win32/Shellex.190111
NANO-AntivirusTrojan.Win32.Kryptik.eykjhu
RisingTrojan.Kryptik!1.AAD1 (CLASSIC)
Ad-AwareGen:Variant.Graftor.464791
EmsisoftGen:Variant.Graftor.464791 (B)
ComodoBackdoor.Win32.Zegost.FH@7qyj9h
F-SecureHeuristic.HEUR/AGEN.1007501
ZillyaTrojan.Kryptik.Win32.995014
Invinceaheuristic
McAfee-GW-EditionPacked-MW!0829CD88FD7C
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusIM-Flooder.Win32.Hityou
JiangminBackdoor.Farfli.cno
AviraHEUR/AGEN.1007501
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.D71797
ZoneAlarmBackdoor.Win32.Farfli.bpoz
MicrosoftTrojan:Win32/Zegost.CJ!bit
Acronissuspicious
VBA32BScope.Trojan.Fsysna
ALYacGen:Variant.Graftor.464791
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM34
TencentMalware.Win32.Gencirc.10b49364
YandexTrojan.Kryptik!9GKMzsdJ0/o
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.FHSE!tr
AVGWin32:Malware-gen
Cybereasonmalicious.8fd7c3
MaxSecureTrojan.Malware.10405594.susgen

How to remove Trojan:Win32/Zegost.CJ!bit?

Trojan:Win32/Zegost.CJ!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment