Backdoor

About “Backdoor.CyberGate” infection

Malware Removal

The Backdoor.CyberGate is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.CyberGate virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Sniffs keystrokes
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Backdoor.CyberGate?


File Info:

crc32: F4CB2A20
md5: c2a1ddaf7e05c6281e9044b6a0e5b0e5
name: server.exe
sha1: c4fc1dc275597d8b91a9310c1baf8370b929eefa
sha256: 6230ca767122c55b63369a5c83a5426756805f66712ce5f5e5fa2a9140030ee2
sha512: a5317ca5db7c0add4529e2f0a67d62b3fdb09e0b82d6ce59a5cb8ebc448f7fa194e0530bda1ab157f50e66d26502b044b9d95631bed6c8d26f847287be3edadd
ssdeep: 6144:7k4qmNz3QeLHBc7iRJOAzuoX+6nmAqlUhLJTB5J0Qr:A94LbjG748OoSLJH1
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor.CyberGate also known as:

MicroWorld-eScanGeneric.Rebhip.3F636FF2
CMCTrojan.Win32.Llac!O
CAT-QuickHealWorm.Rebhip.Z.mue
McAfeeGeneric PWS.ld
MalwarebytesBackdoor.CyberGate
AegisLabTrojan.Win32.Llac.4!c
K7AntiVirusTrojan ( 00193f571 )
BitDefenderGeneric.Rebhip.3F636FF2
K7GWTrojan ( 00193f571 )
Cybereasonmalicious.f7e05c
TrendMicroTSPY_SPATET.SMT
BaiduWin32.Trojan.Agent.co
F-ProtW32/Trojan2.JRCA
SymantecW32.Spyrat
TotalDefenseWin32/Spyrat!generic
APEXMalicious
AvastWin32:Dropper-FJG [Trj]
ClamAVWin.Trojan.Agent-36136
GDataGeneric.Rebhip.3F636FF2
KasperskyTrojan.Win32.Llac.lgnr
AlibabaWorm:Win32/Llac.2f702eef
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472[UPX]
RisingWorm.Rebhip!1.A338 (CLASSIC)
Ad-AwareGeneric.Rebhip.3F636FF2
SophosW32/Rebhip-AR
ComodoTrojWare.Win32.Llac.C@1lpak6
F-SecureBackdoor:W32/Spyrat.A
DrWebBackDoor.Cybergate.1
ZillyaTrojan.Llac.Win32.3684
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareHotBar.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c2a1ddaf7e05c628
EmsisoftGeneric.Rebhip.3F636FF2 (B)
IkarusTrojan.Win32.Llac
CyrenW32/Rebhip.B.gen!Eldorado
JiangminTrojan/Llac.kzj
MaxSecureTrojan.W32.LLAC.BDM
AviraWORM/Rebhip.V
Antiy-AVLTrojan/Win32.Llac.bdm
Endgamemalicious (moderate confidence)
ArcabitGeneric.Rebhip.3F636FF2
SUPERAntiSpywareWorm.Rebhip
ZoneAlarmTrojan.Win32.Llac.lgnr
MicrosoftTrojanSpy:Win32/Rebhip.A!upx
TACHYONTrojan/W32.DP-Llac.308224
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
VBA32Trojan.Llac
ALYacGeneric.Rebhip.3F636FF2
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/Ransom.AB
ZonerTrojan.Win32.60048
ESET-NOD32Win32/Spatet.A
TrendMicro-HouseCallTSPY_SPATET.SMT
TencentTrojan.Win32.Downloader.aat
YandexWorm.DR.Rebhip.Gen
SentinelOneDFI – Malicious PE
eGambitRAT.CyberGate
FortinetW32/Llac.GFU!tr
AVGWin32:Dropper-FJG [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Worm.cd8

How to remove Backdoor.CyberGate?

Backdoor.CyberGate removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment