Backdoor

About “Backdoor.YAI” infection

Malware Removal

The Backdoor.YAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.YAI virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine Backdoor.YAI?


File Info:

name: 7BA77EAC0EF2AEFF7325.mlw
path: /opt/CAPEv2/storage/binaries/a05295a937cf70a809f3ca3a773f1572f9e9b216146cf5874dcdba254512800b
crc32: 0A9996CC
md5: 7ba77eac0ef2aeff73254cdd3879ad20
sha1: bd35382bbee7e9f4ac3caa1a722b9b826adfdb30
sha256: a05295a937cf70a809f3ca3a773f1572f9e9b216146cf5874dcdba254512800b
sha512: ad04db179073e4aa6eb32e2f937b4141ba83523a6f67a3923904739832958cd12a806bcabf0f1b53b8381657edd79d14f4d0c07845aa04dd867fa2a45e0b49d5
ssdeep: 6144:0009vjmGaQITG+BvGebdEYP48VoiH9p4veiet8WB:0PCGaQz+Beydt/Voo9IS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12044125A7385992CE8129BB0579983790710FC456E23C9232764FBEF6E7FB89BB06404
sha3_384: aa82a61b7b93681727d9a8efe7d0bbd4a39d9bc9d8175dfcf618ff896c036ba5dd978a211823378517270ec940b1b827
ep_bytes: 60e8000000005d81ed0a4a4400bb044a
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.YAI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.YAI
ClamAVWin.Trojan.SubSeven-3
FireEyeGeneric.mg.7ba77eac0ef2aeff
ALYacBackdoor.YAI
Cylanceunsafe
ZillyaBackdoor.YAI.Win32.4
SangforBackdoor.Win32.Yai.V3dy
K7AntiVirusTrojan ( 0000374e1 )
K7GWTrojan ( 0000374e1 )
Cybereasonmalicious.c0ef2a
BitDefenderThetaGen:NN.ZelphiF.36196.qOXbamxiL4jb
CyrenW32/Yaiver.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Yaiver
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.YAI
BitDefenderBackdoor.YAI
NANO-AntivirusTrojan.Win32.YAI.brafrn
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b30981
SophosMal/Generic-R
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Yai.723
VIPREBackdoor.YAI
TrendMicroBKDR_YAI.A
McAfee-GW-EditionBehavesLike.Win32.PWSQQPass.dc
EmsisoftBackdoor.YAI (B)
SentinelOneStatic AI – Suspicious PE
GDataBackdoor.YAI
JiangminBackdoor/Yai.b
AviraTR/Spy.Gen
Antiy-AVLTrojan[Backdoor]/Win32.YAI
XcitiumBackdoor.Win32.Yaiver@lw5
ArcabitBackdoor.YAI
ZoneAlarmBackdoor.Win32.YAI
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Yai.R275964
McAfeeBackDoor-ZJ
MAXmalware (ai score=85)
VBA32Trojan.Backdoor
MalwarebytesMalware.AI.2291947490
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_YAI.A
RisingBackdoor.YAI!8.4A93 (TFE:5:4TwcWjXATFU)
YandexBackdoor.YAI!x3ZNBlFFWBM
IkarusTrojan.Win32.Yaiver
MaxSecureTrojan.Malware.1670044.susgen
FortinetW32/YAI.ZM!tr.bdr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.YAI?

Backdoor.YAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment