Malware

About “Zegost.2” infection

Malware Removal

The Zegost.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zegost.2 virus can do?

  • At least one process apparently crashed during execution
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to stop active services
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Zegost.2?


File Info:

crc32: ABEB882E
md5: 8978e0afc5f7b6f48c6ddaedb166997e
name: 8978E0AFC5F7B6F48C6DDAEDB166997E.mlw
sha1: 4764d72bf32fc67936b3d72cc10962d25cea6200
sha256: fe641f750ca91dd3aa0c5be0fd612655431d597eb1f42208e678bd391710bb35
sha512: 65bce1ff655e2ea15a1d5d1dd222d3d6e2963be61b26cb9c4ca8a2f1c339053224995a5446c29d3fa76686e6926198f778331f98c05352143a8746219cd92058
ssdeep: 6144:SsIZ6nW8QIBTyPRqyhYPbncTBlhHrkndnkv0oX:/RW8EJq8YPbncT3X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: SPUNINST.EXE
FileVersion: 6.3.0004.1 built by: dnsrv
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.3.0004.1
FileDescription: Windows Service Pack Uninstall
OriginalFilename: SPUNINST.EXE
Translation: 0x0804 0x04b0

Zegost.2 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Zegost.48
CynetMalicious (score: 100)
CAT-QuickHealTrojanDropper.Zegost.C5
ALYacGen:Variant.Zegost.2
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Bjlog.5cf7098e
Cybereasonmalicious.fc5f7b
BaiduWin32.Backdoor.Zegost.b
CyrenW32/Zegost.L.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Redosdru.FP
APEXMalicious
AvastWin32:Zegost-C [Trj]
ClamAVWin.Trojan.Zegost-9758778-0
KasperskyTrojan-PSW.Win32.Bjlog.dtwr
BitDefenderGen:Variant.Zegost.2
NANO-AntivirusTrojan.Win32.Bjlog.drshei
ViRobotTrojan.Win32.PSWBjlog.200704
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
MicroWorld-eScanGen:Variant.Zegost.2
TencentBackdoor.Win32.Zegost.aaa
Ad-AwareGen:Variant.Zegost.2
SophosML/PE-A + Mal/PWS-GA
ComodoBackdoor.Win32.Zegost.B@1qlsm2
BitDefenderThetaAI:Packer.4D1960461F
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_REDOS.SME
McAfee-GW-EditionBackDoor-CEP.gen.cv
FireEyeGeneric.mg.8978e0afc5f7b6f4
EmsisoftGen:Variant.Zegost.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Bjlog.bvd
AviraTR/PSW.Bjlog.lfzb
eGambitUnsafe.AI_Score_99%
KingsoftHeur.SSC.4709.1216.(kcloud)
MicrosoftTrojanDropper:Win32/Zegost.B
GridinsoftMalware.Win32.Pack.26069!se
ArcabitTrojan.Zegost.2
GDataGen:Variant.Zegost.2
TACHYONTrojan-PWS/W32.Bjlog.209384
AhnLab-V3Dropper/Zegost.206136
Acronissuspicious
McAfeeBackDoor-CEP.gen.cv
MAXmalware (ai score=84)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Dropper
PandaGeneric Malware
TrendMicro-HouseCallTROJ_REDOS.SME
RisingBackdoor.Bjlog!1.D1D9 (CLOUD)
YandexTrojan.GenAsa!lCabc7J0Kjw
IkarusTrojan.Agent
FortinetW32/Bjlog.GL!tr
AVGWin32:Zegost-C [Trj]
Paloaltogeneric.ml
Qihoo-360Dropper.Win32.Zegost.A

How to remove Zegost.2?

Zegost.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment