Trojan

Should I remove “Trojan:Win32/Zegost.CN!bit”?

Malware Removal

The Trojan:Win32/Zegost.CN!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zegost.CN!bit virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
5g.xbt.cn
a.tomx.xyz
users.qzone.qq.com
ocsp.dcocsp.cn
crl.digicert-cn.com
crl3.digicert.com
crl4.digicert.com
i.qq.com

How to determine Trojan:Win32/Zegost.CN!bit?


File Info:

crc32: F9659640
md5: 80ec37f324363d31615576ece9b00e22
name: svchost.exe
sha1: c357b16ceb711b82edd7c1b55e744f55709300bb
sha256: d9aab984aa4a10eb2580117cfc5d25bf2b7125e8d4e18bcb8ec6c8fb13654490
sha512: 00b5114d5fa78eaa4b174da41182f81d34ce86de72fbadc9324b6ab39c7a2f60150d792494e4b5d3c7a38a070be431253c67883b7a12a324465dfeaa4e122a35
ssdeep: 6144:dhH/T7gxqsJYAGWRN17a8cMqnPfbAnbW82HqlamtgbQd8WpVH5/:P7mYAhRFcMmubW8b8mubS7/
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright (C) 2011
InternalName: GameLauncher.exe
FileVersion: 2016,05,30,1
CompanyName: x676dx5ddex987ax7f51x79d1x6280x80a1x4efdx6709x9650x516cx53f8
ProductName: x6e38x620fx542fx52a8x9875
ProductVersion: 1.0.0.8
FileDescription: x6e38x620fx542fx52a8x9875
OriginalFilename: GameLauncher.exe
Translation: 0x0804 0x03a8

Trojan:Win32/Zegost.CN!bit also known as:

MicroWorld-eScanTrojan.Cud.Gen.1
FireEyeGeneric.mg.80ec37f324363d31
McAfeeTrojan-FQHU!80EC37F32436
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0053a09e1 )
BitDefenderTrojan.Cud.Gen.1
K7GWTrojan-Downloader ( 0053a09e1 )
Cybereasonmalicious.324363
Invinceaheuristic
F-ProtW32/Agent.NBNR
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.Cud.Gen.1
KasperskyHEUR:Worm.Win32.Generic
AlibabaWorm:Win32/Zegost.f6665a43
NANO-AntivirusTrojan.Win32.Agent.eljrwm
TencentMalware.Win32.Gencirc.10b44cc7
Ad-AwareTrojan.Cud.Gen.1
EmsisoftTrojan.Cud.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Cacrk.A@6hsf5a
F-SecureHeuristic.HEUR/AGEN.1116253
TrendMicroBKDR_ZEGOST.SM33
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Agent4
CyrenW32/Agent.KBSX-2489
JiangminWorm.Generic.ajtp
WebrootW32.Trojan.Cud.Gen
AviraHEUR/AGEN.1116253
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Cud.Gen.1
ZoneAlarmHEUR:Worm.Win32.Generic
MicrosoftTrojan:Win32/Zegost.CN!bit
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZexaF.34132.Iq0@aKSVrigj
VBA32BScope.TrojanDownloader.Farfli
MalwarebytesBackdoor.Zegost
PandaTrj/CI.A
ZonerTrojan.Win32.82486
ESET-NOD32Win32/TrojanDownloader.Agent.DDW
TrendMicro-HouseCallBKDR_ZEGOST.SM33
RisingBackdoor.BigWolf!1.BBD2 (CLOUD)
YandexTrojan.DL.Agent!AMQJtKHN6HY
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.CGT!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/HEUR/QVM41.2.CE11.Malware.Gen

How to remove Trojan:Win32/Zegost.CN!bit?

Trojan:Win32/Zegost.CN!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment