Backdoor

What is “Backdoor:PHP/OrbWS.WS!MTB”?

Malware Removal

The Backdoor:PHP/OrbWS.WS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:PHP/OrbWS.WS!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Backdoor:PHP/OrbWS.WS!MTB?


File Info:

name: C49C37BBEC29E3476DE2.mlw
path: /opt/CAPEv2/storage/binaries/c14461ba6441b42c3c569463057b2d96c117a3c98396d32dc26ccbe23d9df8a1
crc32: 59562D2C
md5: c49c37bbec29e3476de20b0806324b41
sha1: ebda4bb088e966e09ac9523297dbb773bdb08444
sha256: c14461ba6441b42c3c569463057b2d96c117a3c98396d32dc26ccbe23d9df8a1
sha512: 3095d478999b70116ea0d74709907fba7bbfb8470b84a11af811f023bd1cc5af31ccae806e8a20526bcfb7333776c1e58cdc1811e6fd998643a28fea301daddb
ssdeep: 98304:gog8J86f5eQXFt/vg3N6gWhCckMuMfgu7JeSk1X2IJZskxJjGs43Fv3RJnip:gaNtng3N6fQMRIu7JeSkpJTxx00p
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA363349F9A06B0FED588235E16229F84B42A09EF292DB734188EF97F441C335379767
sha3_384: 77f03a75cae2eb8aae8a6d770f58a85f5f3d6400d620cebb7519cbaacd0c067b664bd2a77d40189434133f8f07d3b340
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Backdoor:PHP/OrbWS.WS!MTB also known as:

BkavW32.AIDetectMalware
McAfeeArtemis!C49C37BBEC29
Cylanceunsafe
SangforTrojan.PHP.Agent.Vcfg
AlibabaBackdoor:PHP/OrbWS.3627dac0
CrowdStrikewin/grayware_confidence_70% (D)
CyrenABRisk.PAUS-6
SymantecTrojan.Gen.MBT
ESET-NOD32PHP/Agent.SA
APEXMalicious
NANO-AntivirusTrojan.Script.Agent.fomlry
ViRobotTrojan.Win.Z.Packed.5000802
AvastPHP:Spambot-A [Trj]
DrWebPHP.Packed.85
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.high.ml.score
SophosTroj/PHPShel-AQ
IkarusBackdoor.PHP.SpamBot
WebrootW32.Malware.Gen
GoogleDetected
Antiy-AVLTrojan[Backdoor]/PHP.OrbWS.ws
GridinsoftTrojan.Win32.Packed.sa
MicrosoftBackdoor:PHP/OrbWS.WS!MTB
CynetMalicious (score: 100)
AhnLab-V3WebShell/PHP.Generic.S1897
VBA32PHP.Packed
MalwarebytesMalware.AI.37006766
TrendMicro-HouseCallTROJ_GEN.R002H01I423
RisingBackdoor.OrbWS/PHP!8.13397 (TOPIS:E0:KNdjrdDaNmT)
AVGPHP:Spambot-A [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:PHP/OrbWS.WS!MTB?

Backdoor:PHP/OrbWS.WS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment