Backdoor

How to remove “Backdoor:Win32/Bezigate.A”?

Malware Removal

The Backdoor:Win32/Bezigate.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bezigate.A virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Bezigate.A?


File Info:

crc32: 6412C980
md5: e7191b8a819e5e5334209a81d51e2fe2
name: E7191B8A819E5E5334209A81D51E2FE2.mlw
sha1: 4ab51f9686fc3ff8582e1ee62ca8c45ad28b3be1
sha256: 4f0976a9577f3a5ed611cac91ca8be3931867fc02b0cc2048baa4157c16019fc
sha512: b5d6582ff91cc8cf9a95367ce83eb34143d4a832267b4944c241662d731897dd838cbb76d2fcd035c46c5063d74ad3eb9da7e4330cb86faa5171d700c75793b8
ssdeep: 384:2rVWSk6jSLHSSSSSSScvVYsSSSSYanSSSSSSSSSSSSSSSSSSSSb1TWztt2odVqs:2r3kRTYPYs20acB1NPUF8N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bezigate.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.844375
FireEyeGeneric.mg.e7191b8a819e5e53
Qihoo-360Win32/Trojan.6b7
ALYacGen:Variant.Razy.844375
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Razy.844375
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-507186
KasperskyTrojan-Ransom.Win32.Foreign.nwuy
NANO-AntivirusTrojan.Win32.Yakes.bdqkxi
AegisLabTrojan.Win32.Yakes.4!c
RisingTrojan.Generic@ML.96 (RDML:zai0Ci3lHeO5keLeqZwxxA)
Ad-AwareGen:Variant.Razy.844375
EmsisoftGen:Variant.Razy.844375 (B)
ComodoMalware@#28uptp1gyngiu
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop4.7151
ZillyaTrojan.Yakes.Win32.7803
McAfee-GW-EditionBehavesLike.Win32.Ardurk.lh
SophosML/PE-A + Mal/EncPk-IF
JiangminTrojan/Yakes.iml
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bezigate.A
ArcabitTrojan.Razy.DCE257
ZoneAlarmTrojan-Ransom.Win32.Foreign.nwuy
GDataGen:Variant.Razy.844375
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gen
Acronissuspicious
McAfeeArtemis!E7191B8A819E
VBA32Malware-Cryptor.General.3
PandaGeneric Malware
TencentWin32.Trojan.Yakes.djnl
YandexTrojan.Delf!V5qBFEoGTs0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_62%
FortinetW32/Yakes.BLNF!tr
BitDefenderThetaAI:Packer.1D30DDE41E
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor:Win32/Bezigate.A?

Backdoor:Win32/Bezigate.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment