Trojan

Trojan:Win32/Zegost.CJ!rfn malicious file

Malware Removal

The Trojan:Win32/Zegost.CJ!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zegost.CJ!rfn virus can do?

  • Executable code extraction
  • Detected script timer window indicative of sleep style evasion
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Zegost.CJ!rfn?


File Info:

crc32: FCF00CFA
md5: 8549dd240c19a51af5767ebaaa1f5ece
name: fre.exe
sha1: 3e781a69581c57c8f0303bb0fdc47b382e6076af
sha256: 55a23f8ee734be3f121e1ef56e38f13325aa6cd3c73258cf59e1cbfab32645cf
sha512: ce2ec50988b4085e58e5d82ca00a48872e688d8d7323e9deb7f8ac47aa775ccaae50185ab984565b2da942c78852321a4379a6b1c00a29ad8bbeae8e62776522
ssdeep: 6144:usJ8sTcnqaGT38Aj7DZlW3jnJ3fx1eDsnp7M2x1ks:uixcntQnDZW3p1e52x1J
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Zegost.CJ!rfn also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Zlob.1.Gen
FireEyeGeneric.mg.8549dd240c19a51a
CAT-QuickHealTrojan.Temr
McAfeeRDN/Generic.grp
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.42525
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Zlob.1.Gen
K7GWTrojan ( 005280591 )
K7AntiVirusTrojan ( 005280591 )
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.Zlob.1.Gen
KasperskyTrojan.Win32.Staser.ctmr
AlibabaBackdoor:Win32/Shellex.190111
NANO-AntivirusTrojan.Win32.GenKryptik.gkuvyd
AegisLabTrojan.Win32.Zlob.4!c
AvastWin32:Hrupka-G [Cryp]
RisingTrojan.Kryptik!1.AAD1 (CLASSIC)
Ad-AwareTrojan.Zlob.1.Gen
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanProxy.Horst.~O@f80r9
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader30.50716
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionBehavesLike.Win32.Sdbot.dc
Trapminemalicious.moderate.ml.score
CMCTrojan-Proxy.Win32.Horst!O
EmsisoftTrojan.Zlob.1.Gen (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.CBZX-6978
JiangminTrojan.Temr.cw
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
Endgamemalicious (moderate confidence)
ArcabitTrojan.Zlob.1.Gen
ZoneAlarmTrojan.Win32.Staser.ctmr
MicrosoftTrojan:Win32/Zegost.CJ!rfn
AhnLab-V3Backdoor/Win32.Zegost.C3859936
Acronissuspicious
ALYacTrojan.Zlob.1.Gen
MAXmalware (ai score=99)
VBA32Trojan.Staser
ESET-NOD32a variant of Win32/GenKryptik.ANNQ
TrendMicro-HouseCallBKDR_ZEGOST.SM34
TencentWin32.Backdoor.Generic.Auto
YandexTrojan.Temr!R4bdo6W2YuE
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.74668089.susgen
FortinetW32/Kryptik.FHSE!tr
BitDefenderThetaGen:NN.ZexaF.34090.pmGfayI3Drh
AVGWin32:Hrupka-G [Cryp]
Cybereasonmalicious.40c19a
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.e4a

How to remove Trojan:Win32/Zegost.CJ!rfn?

Trojan:Win32/Zegost.CJ!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment