Backdoor

Backdoor:MSIL/WebShell.GMF!MTB removal instruction

Malware Removal

The Backdoor:MSIL/WebShell.GMF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/WebShell.GMF!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/WebShell.GMF!MTB?


File Info:

name: 85C69A376CA29553C3C4.mlw
path: /opt/CAPEv2/storage/binaries/2478fba9fbd6fff603515dd3f7ec852c8f60fc1943f64c8e5f8e384138e6ecff
crc32: E8F7915C
md5: 85c69a376ca29553c3c4e1d24b763dd8
sha1: cd944e41f5155591bedd6302e7fabbe572c67834
sha256: 2478fba9fbd6fff603515dd3f7ec852c8f60fc1943f64c8e5f8e384138e6ecff
sha512: 190c647dbe95d741bb32ad39ffd776ae65dfa08edec4087652fbb4f78fcc394d24e2400dc73bab103c43c4d991b66a07c9aadf285a2c5825a34cf23f5d971082
ssdeep: 3072:MIJCJkzd6AHplfnXSJMT+qsyGQUeiXUyWmrjYcr6gytmAZsF1i9LC8Y:MOzd6A/66gfF1Q
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T146240837F1F0871CE1F996BF55B54D208776B906A923C51E1C98B4AE0BB2BCC8826F51
sha3_384: 70341d3de3f6b3f3c574d62fb7e18483f50d3896e5225083dbdd282a877d3db0bcb6e8cc585eabdc4d73f502c86b433a
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-05-02 22:26:03

Version Info:

0: [No Data]

Backdoor:MSIL/WebShell.GMF!MTB also known as:

BkavW32.AIDetectMalware.CS
AVGWin32:BackdoorX-gen [Trj]
Elasticmalicious (high confidence)
DrWebBackDoor.WebshellNET.8
MicroWorld-eScanGen:Variant.Tedy.317234
FireEyeGen:Variant.Tedy.317234
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Tedy.317234
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bd1 )
K7GWTrojan ( 005ab4bd1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Webshell.AU
APEXMalicious
ClamAVWin.Packed.Bulz-9891413-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderGen:Variant.Tedy.317234
AvastWin32:BackdoorX-gen [Trj]
EmsisoftGen:Variant.Tedy.317234 (B)
F-SecureHeuristic.HEUR/AGEN.1362733
ZillyaTrojan.Webshell.Win32.20508
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.PSE.13FRN7X
VaristW32/WebShell.D.gen!Eldorado
AviraHEUR/AGEN.1362733
MAXmalware (ai score=83)
Antiy-AVLTrojan/MSIL.WebShell
ArcabitTrojan.Tedy.D4D732
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
MicrosoftBackdoor:MSIL/WebShell.GMF!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5541401
ALYacGen:Variant.Tedy.317234
TACHYONBackdoor/W32.DN-WebShell.217088.D
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DE424
TencentBackdoor.MSIL.WebShell.16000622
IkarusTrojan.MSIL.Webshell
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Webshell.AZ!tr
DeepInstinctMALICIOUS
alibabacloudBackdoor:MSIL/Webshell.AU

How to remove Backdoor:MSIL/WebShell.GMF!MTB?

Backdoor:MSIL/WebShell.GMF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment