Threat Database Backdoors Backdoor.Zegost.CLB

Backdoor.Zegost.CLB

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 23,112
Threat Level: 60 % (Medium)
Infected Computers: 3
First Seen: December 8, 2022
Last Seen: June 9, 2026
OS(es) Affected: Windows

The detection of Backdoor.Zegost.CLB on your system indicates a potentially serious security threat. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malware infections, data theft, or other malicious activities. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future occurrences.

What Is Backdoor.Zegost.CLB?

Backdoor.Zegost.CLB is a type of malware that creates a secret doorway into your computer system, allowing hackers to remotely access and control your computer without your knowledge or consent. This backdoor can be used to steal sensitive information, install additional malware, or use your computer as a botnet to conduct malicious activities. The name Backdoor.Zegost.CLB itself does not directly indicate a specific malware family, but rather describes the type of threat it poses.

How Backdoor.Zegost.CLB Operates

Backdoor.Zegost.CLB operates by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing it. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. It may also attempt to hide its presence by disguising itself as a legitimate program or process. The backdoor can be used to download and install additional malware, creating a complex and resilient threat that requires thorough removal efforts.

Symptoms of Infection

Symptoms of a Backdoor.Zegost.CLB infection can be subtle, but they may include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unexpected outgoing connections or data transfers. In some cases, the backdoor may attempt to manipulate your system settings or disable security software to maintain its presence.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased network activity or unusual data transfers
  • System crashes or instability

How to Remove Backdoor.Zegost.CLB

  1. Boot your computer in Safe Mode with Networking to prevent the backdoor from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove all instances of the backdoor and any related malware.
  3. Uninstall any suspicious programs or applications that may be related to the backdoor infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the backdoor has been completely removed.

Conclusion

Removing Backdoor.Zegost.CLB requires a thorough and multi-step approach to ensure that all instances of the malware are eliminated and your system is secure. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong passwords, and being cautious when clicking on links or downloading attachments, you can help protect your computer from future malware infections and maintain a safe and secure online experience.

Analysis Report

General information

Family Name: Backdoor.Zegost.CLB
Signature status: No Signature

Known Samples

MD5: 206b3cd4ee66423d0d6c313629f561b8
SHA1: b0414769e528519d63f33151da695d1c2aa392d9
SHA256: BEF97D38BE40733E1D530A3E5D0397A4D82C8307014EEFC71207031DEF73AF02
File Size: 52.22 KB, 52224 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments FreeEIM
Company Name FEIM Studios
File Description A Free Enterprise Instant Messenger
File Version 3, 5, 0, 1
Internal Name freeeim
Legal Copyright Copyright (C) 2010 FEIM Studios
Original Filename freeeim.exe
Product Name FreeEIM
Product Version 3, 5, 0, 1
Special Build Simple Chinese

File Traits

  • dll
  • x86

Block Information

Total Blocks: 48
Potentially Malicious Blocks: 33
Whitelisted Blocks: 15
Unknown Blocks: 0

Visual Map

x x 0 x x 0 0 x x x x x x x x 0 x x x x x x 0 x x x 0 x x x x x x x x x 0 x 0 x 0 0 x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Farfli.FH
  • Zegost.CLB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b0414769e528519d63f33151da695d1c2aa392d9_0000052224.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...