Spy

Spyware.WebShell malicious file

Malware Removal

The Spyware.WebShell is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.WebShell virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Spyware.WebShell?


File Info:

name: EF9108EE0537670EB563.mlw
path: /opt/CAPEv2/storage/binaries/cdfe91f51cabd883d403d0792fa9ba994314841a750e7889f653065bb970b80a
crc32: 015BFCBD
md5: ef9108ee0537670eb56384bc834a84da
sha1: 4b05a6b43f8b505120da272dc9a13821151a1d62
sha256: cdfe91f51cabd883d403d0792fa9ba994314841a750e7889f653065bb970b80a
sha512: 73639beaaaa22eccefa065384e5fc0190aa9e228680a3db49ffb6c4e56d41c18ffd625da9ca892d4440e62a71ba81c416a4b080cc0ef4f14c24e13c4cb8ba7a2
ssdeep: 384:7RvT0KQb6fLeML1gaXWTmxOtKX7Lt4TpTyLt:7WKbfLDphmKxOtKne9y
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T12262C61BAB89CD13C6BBA33267B69604D5B695030552CB1EBDDCA5CA1F733044262FC8
sha3_384: 92f2ead14bcedc5c9cabfd083ef490f2675aa062d1bf1f558833ff56554d87392aeb2e33256d3c8dbcd9b42650b88071
ep_bytes: ff250020001000000000000000000000
timestamp: 2024-01-31 13:05:10

Version Info:

0: [No Data]

Spyware.WebShell also known as:

BkavW32.AIDetectMalware.CS
AVGWin32:BackdoorX-gen [Trj]
Elasticmalicious (high confidence)
DrWebBackDoor.WebshellNET.9
MicroWorld-eScanGen:Variant.MSILHeracles.92481
FireEyeGen:Variant.MSILHeracles.92481
CAT-QuickHealBackdoor.WebShell
SkyhighBehavesLike.Win32.BadFile.lm
McAfeeArtemis!EF9108EE0537
Cylanceunsafe
ZillyaTrojan.Webshell.Win32.16502
K7GWTrojan ( 005b19ee1 )
K7AntiVirusTrojan ( 005b19ee1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Webshell.EV
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Packed.Webshell-10016062-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderGen:Variant.MSILHeracles.92481
TencentBackdoor.MSIL.WebShell.kae
EmsisoftGen:Variant.MSILHeracles.92481 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
VIPREGen:Variant.MSILHeracles.92481
TrendMicroTROJ_GEN.R03BC0DDE24
SophosMal/Generic-S
VaristW32/WebShell.E.gen!Eldorado
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=87)
MicrosoftBackdoor:MSIL/Webshell.BB!MTB
ArcabitTrojan.MSILHeracles.D16941
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataMSIL.Trojan.PSE.14W6LGL
GoogleDetected
AhnLab-V3Backdoor/Win.WEBSHELL.C5557105
ALYacGen:Variant.MSILHeracles.92481
TACHYONBackdoor/W32.DN-WebShell.15872.P
MalwarebytesSpyware.WebShell
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DDE24
IkarusTrojan.MSIL.Webshell
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Webshell.EE!tr
DeepInstinctMALICIOUS
alibabacloudBackdoor:MSIL/godzilla.Webshell.A

How to remove Spyware.WebShell?

Spyware.WebShell removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment