The solution is to do some research on what is being uploaded. Part of the script in question contains the words "FTP Brute," as in "brute force an FTP password." There is no legitimate reason for this to be on the server.
Part of the "web shells" is supposedly security testing. Our way to stay secure against webshells such as these is to simply revoke all access to the accounts with it on them. Problem solved.
If you ever find anything that says "shell script," assume it will get you permanently suspended due to it being considered a virus in some antivirus software, and downright malicious by any other standard. When in doubt, ASK FIRST.