Backdoor

Backdoor.Generic.1009001 removal tips

Malware Removal

The Backdoor.Generic.1009001 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.1009001 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Backdoor.Generic.1009001?


File Info:

name: 780C2844D3E255C0C962.mlw
path: /opt/CAPEv2/storage/binaries/02e8472539c8382b96470cf5eab81afdc762f8ba53b76d96eee844cd93b440b5
crc32: 6522C5BE
md5: 780c2844d3e255c0c96288f17fd8d4f8
sha1: 053e46aae0442e472e64c81214420c1ccfeb8f6a
sha256: 02e8472539c8382b96470cf5eab81afdc762f8ba53b76d96eee844cd93b440b5
sha512: be3099fca25837af2020e58b68bca0f7d62d55cc32fa68821aefe68e0d05022b90bc40d11baebc49953904623dc44912a12a04d5d0adccd4b52b6bdedd1573b4
ssdeep: 49152:ZWVOcE2DXdbr73PxrM198r2p4i6us70HfVBjeGfjAhWFcBuy:ZWV42Frz2Hba7UfbjeGqWFby
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E167953EEDED871E4EE0130CCE67A5B8D11EC0018BD4F0BE465BB39FAE6D5204A5296
sha3_384: 2bc31c113e32fc84d53b654a5dde3a4c1a6bafc020771d8de8472780624fb0eac94aa474c340cbdb6cbaad8d710c933b
ep_bytes: 558bec83c4e453565733c08945e48945
timestamp: 2013-02-04 23:06:48

Version Info:

CompanyName: EMV Writer Software by Paws
FileDescription: EMV Chip Writer
FileVersion: 10.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0416 0x04e4

Backdoor.Generic.1009001 also known as:

LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Generic.1009001
FireEyeGeneric.mg.780c2844d3e255c0
McAfeeArtemis!780C2844D3E2
CylanceUnsafe
SangforTrojan.Win32.Heuristic.rg
K7AntiVirusTrojan-Downloader ( 004d688a1 )
AlibabaBackdoor:MSIL/Bladabindi.3a6ae89b
K7GWTrojan-Downloader ( 004d688a1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32VBS/TrojanDropper.Agent.NHN
TrendMicro-HouseCallTROJ_GEN.R002C0GAV22
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.Bladabindi.ius
BitDefenderBackdoor.Generic.1009001
NANO-AntivirusTrojan.Win32.Bladabindi.enouzu
AvastWin32:Malware-gen
RisingBackdoor.Njrat!8.2548 (CLOUD)
Ad-AwareBackdoor.Generic.1009001
EmsisoftBackdoor.Generic.1009001 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GAV22
McAfee-GW-EditionBehavesLike.Win32.BadFile.rh
SophosMal/Generic-S
IkarusBackdoor.MSIL.Bladabindi
JiangminWorm.VBS.aad
WebrootW32.Trojan.GenKD
AviraBDS/Bladabindi.qahkq
MicrosoftBackdoor:MSIL/Bladabindi
ZoneAlarmBackdoor.MSIL.Bladabindi.ius
GDataBackdoor.Generic.1009001
CynetMalicious (score: 99)
VBA32Backdoor.MSIL.Bladabindi
ALYacBackdoor.Generic.1009001
MAXmalware (ai score=100)
APEXMalicious
TencentMsil.Backdoor.Bladabindi.Afro
YandexBackdoor.Bladabindi!Ia6dQ8aeL0c
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Script.GENERIC!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Backdoor.Generic.1009001?

Backdoor.Generic.1009001 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment