Backdoor

Backdoor.MotivFTP malicious file

Malware Removal

The Backdoor.MotivFTP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MotivFTP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Backdoor.MotivFTP?


File Info:

name: 0AEDC9C0F482BED4103C.mlw
path: /opt/CAPEv2/storage/binaries/2fa01587baf406b32bb71661ac7b4e8ade29bd7645106996323824cc9cd03579
crc32: 58F8C9E7
md5: 0aedc9c0f482bed4103c498d670f88bf
sha1: 432d0a391e180ef82eb113918ae931f2f3b8324e
sha256: 2fa01587baf406b32bb71661ac7b4e8ade29bd7645106996323824cc9cd03579
sha512: f9462f518b888a2bdd21adf0e5b3c3b11bc75daa2fd163bcfddd562cf9878254531dec6ac72362864268e8f0e376137d7cf7f44a52b23e635a4f1fabafb22a9b
ssdeep: 24576:6EohRE1rmZWRbfSrvVW9vyq7lVgtDT4QUrTSeKyJmJiJEGwqjSbdmb0CZD6gEUAD:2+df7lVgXUaeKNJ65MoDNHAD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A65235E536F8A23C6172E3A4973B21B852B8C77C37A17AAA1C5B71408377D08F3D199
sha3_384: ca6ba7b7e2b8c65aec6b555435c822da73c5cb3c572c5afdd977ae2e0b06dea6080672dc9af7f39f15043ff4ff01a0f3
ep_bytes: 64a100000000558bec6aff6808404000
timestamp: 1998-10-13 04:20:24

Version Info:

0: [No Data]

Backdoor.MotivFTP also known as:

LionicTrojan.Win32.MotivFTP.4!c
CylanceUnsafe
VirITBackdoor.Win32.FTP.AU
CyrenW32/Backdoor.JHTY-5763
SymantecTrojan.Gen.2
Paloaltogeneric.ml
ClamAVWin.Trojan.Genome-3086
NANO-AntivirusTrojan.Win32.Motiv.fjufug
AvastFileRepMalware
DrWebBackDoor.Motiv.14
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
IkarusBackdoor.Win32.MotivFTP
JiangminBackdoor/MotivFTP.b
Antiy-AVLTrojan/Generic.ASMalwS.7BD6D5
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotBackdoor.Win32.MotivFTP_12
McAfeeArtemis!0AEDC9C0F482
VBA32Backdoor.MotivFTP
RisingBackdoor.MotivFTP.12.a (CLASSIC)
AVGFileRepMalware

How to remove Backdoor.MotivFTP?

Backdoor.MotivFTP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment