Remove Bebshell. Description and removal instructions

 
Title: Bebshell

Type: Backdoors
Severity scale:Bebshell severity is 71  (71 / 100)
 
Bebshell is a backdoor that provides the attacker with unauthorized remote access to the compromised computer. The intruder can manipulate files, start and end processes, log keystrokes and send e-mail messages. The backdoor also allows to steal e-mail account details, retrieve network and drive information and modify system configuration by altering the Windows registry. Bebshell runs on every Windows startup.

Bebshell is usually installed through the WMF exploit.


Bebshell properties:
• Allows remote user connection
• Sends out logs by FTP or email
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Bebshell removal:

remover for Bebshell

Bebshell manual removal:

Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\webshell
HKEY_CLASSES_ROOT\CLSID\[random string]\InProcServer32\(Default)=%System%\webshell.dll
Unregister DLLs:
webshell.dll

Delete files:
webshell.dll, winlog.dll, w jan 20.doc
Misc:
Exact file location:
w jan 20.doc - C:\Windows\Temp or C:\Winnt\Temp
webshell.dll, winlog.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Bebshell:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 25/02/06
Information updated: 25/02/06

Additional resources related to Bebshell:

Attention: If you know or you have a website or page about Bebshell removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Bebshell parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: