Backdoor

Backdoor.MSIL.ReverseShell.i information

Malware Removal

The Backdoor.MSIL.ReverseShell.i is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.ReverseShell.i virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Backdoor.MSIL.ReverseShell.i?


File Info:

name: C27139841E5FF1AE91F5.mlw
path: /opt/CAPEv2/storage/binaries/6b7f7e741e88caa8d61d8eed79890b0272f888261c72dbaa5391e6990172be10
crc32: C87914F8
md5: c27139841e5ff1ae91f57ceb4fedc621
sha1: 2e77d8e3ca8fb8bff0fd39a2c8fdbc3d163a8482
sha256: 6b7f7e741e88caa8d61d8eed79890b0272f888261c72dbaa5391e6990172be10
sha512: 8366663843c47779d85f22ae25114e8329365e6a289dab1e09c0cc915b51d99b2e2868a2a0e9079ab60154ffe1a144c0b0f21ef270aad003ca229dda8a44f91f
ssdeep: 96:eo2H5MqOxVlKmYnII2P4HMxOBCb1brkSnMF/yZuwun/SP9ezNt:en5+Yk4CbBcKsFnE4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T106D1C522F3D48336CCA60AB4EDA2634057B4EB958D67EF6E3C88E5476C873144622771
sha3_384: 85348bbb09fc8fa4147d5f3ea29947ac2ce45e3eca914332b761b93364918bcc2c6aa425f61e81df4e8eb07c9d2fa2e1
ep_bytes: ff250020400000000000000000000000
timestamp: 2049-08-20 17:30:57

Version Info:

Translation: 0x0000 0x04b0
CompanyName: ConsoleApp1
FileDescription: ConsoleApp1
FileVersion: 1.0.0.0
InternalName: ConsoleApp1.dll
LegalCopyright:
OriginalFilename: ConsoleApp1.dll
ProductName: ConsoleApp1
ProductVersion: 1.0.0
Assembly Version: 1.0.0.0

Backdoor.MSIL.ReverseShell.i also known as:

LionicTrojan.Win32.Agent.Y!c
AVGWin32:BackdoorX-gen [Trj]
Elasticmalicious (high confidence)
McAfeeRDN/Generic BackDoor
MalwarebytesBackdoor.AsyncRAT
ZillyaTrojan.Evilnum.Win32.493
SangforBackdoor.Msil.Reverseshell.V22s
K7AntiVirusTrojan ( 0056dc2b1 )
AlibabaBackdoor:MSIL/ReverseShell.9746c3db
K7GWTrojan ( 0056dc2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Troj.BGA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Evilnum.B
CynetMalicious (score: 100)
KasperskyBackdoor.MSIL.ReverseShell.i
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.13bf923f
F-SecureTrojan.TR/Redcap.fjecn
TrendMicroTROJ_GEN.R002C0DD923
McAfee-GW-EditionRDN/Generic BackDoor
SophosMal/Generic-S
IkarusTrojan.MSIL.Evilnum
JiangminBackdoor.MSIL.gdqw
WebrootW32.Trojan.Gen
AviraTR/Redcap.fjecn
Antiy-AVLTrojan/MSIL.Evilnum
ViRobotTrojan.Win.Z.Evilnum.6656
ZoneAlarmBackdoor.MSIL.ReverseShell.i
MicrosoftVirTool:MSIL/Mousewe.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Mousewe.C5033755
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DD923
RisingBackdoor.Small!8.21B (CLOUD)
YandexTrojan.Evilnum!7xuM0ucuraE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Evilnum.B!tr
DeepInstinctMALICIOUS

How to remove Backdoor.MSIL.ReverseShell.i?

Backdoor.MSIL.ReverseShell.i removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment