Backdoor Spy

How to remove “Backdoor.MSIL.SpyGate.ylq”?

Malware Removal

The Backdoor.MSIL.SpyGate.ylq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.SpyGate.ylq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family

How to determine Backdoor.MSIL.SpyGate.ylq?


File Info:

name: 742712173C5DBD2E09C1.mlw
path: /opt/CAPEv2/storage/binaries/581fcc68b3f902ab823b6f40c9e5d471fba6d7cc529a2f2f7b444ae3046c1753
crc32: 4CD999EA
md5: 742712173c5dbd2e09c1134eb7044ac8
sha1: bb4c23e5fcc54ea02e0007fbacfcb3dc735ce764
sha256: 581fcc68b3f902ab823b6f40c9e5d471fba6d7cc529a2f2f7b444ae3046c1753
sha512: 35468604f72d4ac2144adacbb2a8cf7d4be25d3bf0c1c26f3d8e78be5cdfc443add7571d506b84505fdbe1b42d6d4b1f5e5ac110786dfddddea0829887ba9291
ssdeep: 98304:aviz/27qWGq/TzuqCDl2Ptao7jSy1rKNf:aviq75/TzufS4Nf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADF5334675C8013BC0B003B114FD23971BE8BCB1235997C7A0CF65AA591A4F17BBABDA
sha3_384: 9e9522efe61084947ad39bb7e72c06ef0afdf8f383d873b997120853df12ebda2600b755097d265e53187b9132b6c9d9
ep_bytes: e81c060000e94dfdffffcccccccccc3b
timestamp: 2009-07-13 23:42:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 8.00.7600.16385 (win7_rtm.090713-1255)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Windows® Internet Explorer
ProductVersion: 8.00.7600.16385
Translation: 0x0419 0x04b0

Backdoor.MSIL.SpyGate.ylq also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.SpyGate.m!c
MicroWorld-eScanTrojan.Dropper.ZNM
ALYacTrojan.Dropper.ZNM
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaBackdoor:MSIL/SpyGate.8e13f96c
CrowdStrikewin/malicious_confidence_70% (W)
CyrenDropper.BJYT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RVD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-6895514-0
KasperskyBackdoor.MSIL.SpyGate.ylq
BitDefenderTrojan.Dropper.ZNM
NANO-AntivirusTrojan.Win32.SpyGate.eyvope
AvastWin32:Malware-gen
ComodoMalware@#1vjxbe5e1945e
DrWebTrojan.DownLoader26.36636
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.742712173c5dbd2e
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Cab
GDataTrojan.Dropper.ZNM
ArcabitTrojan.Dropper.ZNM
MicrosoftBackdoor:MSIL/Bladabindi
McAfeeArtemis!742712173C5D
MAXmalware (ai score=89)
TencentMsil.Backdoor.Spygate.Aexr
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.RVD!tr
AVGWin32:Malware-gen
Cybereasonmalicious.73c5db

How to remove Backdoor.MSIL.SpyGate.ylq?

Backdoor.MSIL.SpyGate.ylq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment