Malware

Should I remove “Win32:Zegost-C [Trj]”?

Malware Removal

The Win32:Zegost-C [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Zegost-C [Trj] virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

ilo.brenz.pl
vip79318901.f3322.net
poujjo.com
ant.trenz.pl
ozpdik.com
doeyim.com
yauhgg.com
yqhiqa.com
utagrd.com
neuiru.com
ymdeuf.com
uztacu.com
ljygtu.com
aslpvf.com
hkascy.com
rfomoy.com
rhmyuc.com
jiiida.com
mzuabo.com
suldwq.com
nohomd.com
dggeau.com
viuuwb.com
msyxgx.com
yynpeg.com
aaylxi.com
hgtfny.com
ekhpae.com
riywre.com
isvroa.com
yrckzg.com
vfxbrm.com
esadgg.com
frazkv.com
oqaeds.com
ujveai.com
slyooy.com
feoymq.com
dkiuvz.com
ahoruh.com
xpoftk.com
wewxwg.com
dxcbwk.com
ecocku.com
uuyfnq.com
avugvi.com
hqnoxo.com
gkloqk.com
otzeud.com
teggyo.com
polekh.com
crdggk.com
eziquy.com
biejfi.com
loarrw.com
oeiqug.com
sbazdj.com
gfsbci.com
sugmjz.com
gxojpz.com
xmxeux.com
agvkdp.com
vtyaya.com
iuwtvq.com
gfbpmk.com
beofxs.com
eypokx.com
urxmyy.com
nkopix.com
lammzi.com
lgyjsu.com
aouajy.com
owqcey.com
uurxzh.com
tjkrok.com
vbzmgr.com
ggktbk.com
qukbmu.com
byubcp.com
ijejgh.com
eijrbh.com
ngfeit.com
ihqejl.com
oucayl.com
ksrard.com
sxcnvn.com
utjqon.com
leeyrd.com
yboern.com
usjfau.com
denttw.com
ytieew.com
hvkqqp.com
rovelw.com
ilitgy.com
uyrgip.com
hmyldw.com
owoelo.com
cixbmh.com
gzyias.com
uuyrzz.com
budfeb.com
goytlo.com

How to determine Win32:Zegost-C [Trj]?


File Info:

crc32: 6DE6D027
md5: ae418cbd687838f4e3b5453da67d48e6
name: sa1.exe
sha1: 2b091d99d8ca6f8a4ecaffc06300dd224d291fe5
sha256: ec20ec663f9f32fc92edf9782f24fb2f4bb7facd4e82d353ae1b906ad9514e76
sha512: b4903256af1f7479aaf4ae5aae39708c5bd526e92a84a5fa5b17aea2bc570b58e608b17ddf2c0314d37fd464e2ea846f00d45f83effd13db9fbef803ec601a32
ssdeep: 3072:zo53onWdOMQHmbGXnhCTz4T02P56yTnxriOt4TBftlSjNL5i4sxuHoOCp5W:zo53onWd/xzz4Y2P5cOt4TBll9uHU5W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: cipher
FileVersion: 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 5.2.3790.3959
FileDescription: File Encryption Utility
OriginalFilename: CIPHER.EXE
Translation: 0x0804 0x04b0

Win32:Zegost-C [Trj] also known as:

BkavW32.Vetor.PE
MicroWorld-eScanWin32.Virtob.Gen.12
FireEyeGeneric.mg.ae418cbd687838f4
CAT-QuickHealW32.Virut.G
McAfeeW32/Virut.n.gen
CylanceUnsafe
VIPREVirus.Win32.Virut.ce.5 (v)
SangforMalware
K7AntiVirusTrojan ( 005376ae1 )
AlibabaVirus:Win32/Virut.17eae0db
K7GWTrojan ( 005376ae1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroPE_VIRUX.R
BitDefenderThetaAI:FileInfector.C9457D4313
CyrenW32/Agent.CC.gen!Eldorado
SymantecW32.Virut.CF
ESET-NOD32Win32/Virut.NBP
BaiduWin32.Virus.Virut.gen
TrendMicro-HouseCallPE_VIRUX.R
AvastWin32:Zegost-C [Trj]
KasperskyVirus.Win32.Virut.ce
BitDefenderWin32.Virtob.Gen.12
NANO-AntivirusVirus.Win32.Virut.hpeg
AegisLabVirus.Win32.Virut.lDdp
TencentVirus.Win32.Virut.Gen.200001
Endgamemalicious (high confidence)
SophosW32/Scribble-B
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Virut.56
ZillyaVirus.Virut.Win32.1938
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Virut.dh
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
CMCVirus.Win32.Virut.1!O
EmsisoftWin32.Virtob.Gen.12 (B)
APEXMalicious
F-ProtW32/Agent.CC.gen!Eldorado
JiangminWin32/Virut.bt
eGambitUnsafe.AI_Score_99%
AviraW32/Virut.Gen
FortinetW32/Virtu.F
Antiy-AVLVirus/Win32.Virut.ce
KingsoftWin32.Virut.dd.368640
MicrosoftVirus:Win32/Virut.BN
AhnLab-V3Win32/Virut.F
ZoneAlarmVirus.Win32.Virut.ce
TACHYONVirus/W32.Virut.Gen
TotalDefenseWin32/Virut.17408
Acronissuspicious
VBA32Virus.Virut.14
MAXmalware (ai score=87)
Ad-AwareWin32.Virtob.Gen.12
PandaW32/Sality.AO
RisingVirus.Virut!1.A08B (CLOUD)
YandexWin32.Virut.AB.Gen
IkarusVirus.Win32.Ramnit
MaxSecureVirus.Virut.CE
GDataWin32.Virtob.Gen.12
WebrootW32.Infector.Virut.Gen
AVGWin32:Zegost-C [Trj]
Cybereasonmalicious.d68783
Paloaltogeneric.ml
Qihoo-360Virus.Win32.VirutChangeEntry.A

How to remove Win32:Zegost-C [Trj]?

Win32:Zegost-C [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment