Backdoor

What is “Backdoor:MSIL/Chopper.FB!dha”?

Malware Removal

The Backdoor:MSIL/Chopper.FB!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Chopper.FB!dha virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/Chopper.FB!dha?


File Info:

name: 27AA3BF1C6E8D23F226A.mlw
path: /opt/CAPEv2/storage/binaries/6950cd58a7a62a35faf0f2ea6f06561b344b1693319b723c8c588a19b1c28b08
crc32: 865DCE24
md5: 27aa3bf1c6e8d23f226a5b56abd9a518
sha1: 61e8a62761ee327ded06ceaf0c5d05a4b879585e
sha256: 6950cd58a7a62a35faf0f2ea6f06561b344b1693319b723c8c588a19b1c28b08
sha512: ed9eb6f8802dfc179834285bb03afc82078ce2ab437f560ace50944f4ecd4be8acc0e0b549a11f7f9da8dd9fbd1766ae2403bc5965167ce229b703a4919bd6b1
ssdeep: 384:vcBe43j1MT0aBenFhC7+2qKxN4TkRGYAHYnL28/YmDjxkhwoUlH1kAYQtkdCc1:vcB93k0WenFhCVq2lq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DBA250023AE99155D8BF5B3B2472418253BBEB0B5A75CF1C25BC159C8F13A039793BB2
sha3_384: 1655f6ca56059d3a624739e05b803d240cc44f0f569394a1ca624792592d4eed55a761701513275a3b6423d1421e535d
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-12-30 13:14:58

Version Info:

Translation: 0x007f 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.0
InternalName: App_Web_x5qf5tv0.dll
LegalCopyright:
LegalTrademarks:
OriginalFilename: App_Web_x5qf5tv0.dll
ProductName:
ProductVersion:

Backdoor:MSIL/Chopper.FB!dha also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Chopper.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.MSIL.Chopper.A.31FCE81D
FireEyeGeneric.mg.27aa3bf1c6e8d23f
SkyhighArtemis!Trojan
McAfeeArtemis!27AA3BF1C6E8
Cylanceunsafe
VIPREGeneric.MSIL.Chopper.A.31FCE81D
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Chopper.c19714e4
K7GWTrojan ( 0057b4fe1 )
K7AntiVirusTrojan ( 0057b4fe1 )
ArcabitGeneric.MSIL.Chopper.A.31FCE81D
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Webshell.AA
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Webshell.gen
BitDefenderGeneric.MSIL.Chopper.A.31FCE81D
NANO-AntivirusTrojan.Win32.Webshell.kgiosb
AvastWin32:BackdoorX-gen [Trj]
TencentMsil.Backdoor.Webshell.Vgil
EmsisoftGeneric.MSIL.Chopper.A.31FCE81D (B)
F-SecureTrojan.TR/Webshell.ispsu
DrWebBackDoor.WebshellNET.1
ZillyaTrojan.Webshell.Win32.18537
TrendMicroTROJ_GEN.R011C0DA124
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/MSIL_Troj.BKP.gen!Eldorado
AviraTR/Webshell.ispsu
Antiy-AVLTrojan/MSIL.WebShell
MicrosoftBackdoor:MSIL/Chopper.FB!dha
ZoneAlarmHEUR:Backdoor.MSIL.Webshell.gen
GDataGeneric.MSIL.Chopper.A.31FCE81D
GoogleDetected
AhnLab-V3Backdoor/Win.Chopper.C5569454
VBA32Backdoor.MSIL.Webshell.Heur
ALYacGeneric.MSIL.Chopper.A.31FCE81D
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3636712511
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DA124
YandexTrojan.Webshell!SEEaxkB2p5I
IkarusBackdoor.MSIL.Chopper
MaxSecureTrojan.Malware.8426628.susgen
FortinetMSIL/Webshell.AA!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:MSIL/Chopper.FB!dha?

Backdoor:MSIL/Chopper.FB!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment