Backdoor

Backdoor.RemShell information

Malware Removal

The Backdoor.RemShell is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.RemShell virus can do?

  • Authenticode signature is invalid

How to determine Backdoor.RemShell?


File Info:

name: 1BBB7F01F3AD0EB81CC1.mlw
path: /opt/CAPEv2/storage/binaries/783955a42ef6ccff3ba4066a24b21ed861dc63f8c59a1ea1165abe80215b2261
crc32: 4B9D59BD
md5: 1bbb7f01f3ad0eb81cc1bcb414cc36dd
sha1: cbf603142046fcbd02a71da695e9a4430c6cf739
sha256: 783955a42ef6ccff3ba4066a24b21ed861dc63f8c59a1ea1165abe80215b2261
sha512: 68190c880e87846dd54e1014849334a8e5df85c39e74a4c8b2acf2ad3452f00e9c8740f24c686647d64510cb61eaa11d4db46b5c09e3edd38465e69b22429659
ssdeep: 1536:g0AVp7q+rHc8RkyzFS8gNP0NIi6bSQ8OoAKYDPZRM1UitZR18:dAV8wHc8RZzFPk2I111KYTI1Uk18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCB36C89F54BE285D41C0D30D291C0E14F7A6C9BBDC958ABBFE0761E59E3212B463A37
sha3_384: c12e62fb326f2e2fc9e100824647f4a359b4e803b1190bd0cb291d1a99bbac7f88fb8416fb064274c2d72f377f7688a2
ep_bytes: 8bec609ce9e02100000068903d400064
timestamp: 2012-07-18 02:46:58

Version Info:

0: [No Data]

Backdoor.RemShell also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.gqW@YgB026ni
CylanceUnsafe
VIPREGen:Trojan.Heur.gqW@YgB026ni
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/MalOb.7aed7da1
Cybereasonmalicious.1f3ad0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Small.NMV
APEXMalicious
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Trojan.Heur.gqW@YgB026ni
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.A.Agent.24576.ET
MicroWorld-eScanGen:Trojan.Heur.gqW@YgB026ni
AvastWin32:MalOb-FE [Cryp]
TencentWin32.Trojan.Agen.Qqil
Ad-AwareGen:Trojan.Heur.gqW@YgB026ni
EmsisoftGen:Trojan.Heur.gqW@YgB026ni (B)
F-SecureHeuristic.HEUR/AGEN.1246196
DrWebBackDoor.RemShell.5
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.1bbb7f01f3ad0eb8
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1246196
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Heur.EE0B9C
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataGen:Trojan.Heur.gqW@YgB026ni
GoogleDetected
Acronissuspicious
MAXmalware (ai score=82)
VBA32Backdoor.RemShell
MalwarebytesGeneric.Worm.AutoRun.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CKM22
RisingBackdoor.Hupigon!8.B57 (TFE:4:0KrkP0A8pbD)
YandexTrojan.GenAsa!g6OyMgzs+gE
IkarusTrojan-PWS.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaAI:Packer.5F2832C41C
AVGWin32:MalOb-FE [Cryp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.RemShell?

Backdoor.RemShell removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment