Backdoor

How to remove “Backdoor.MSIL.Bladabindi.bvtp”?

Malware Removal

The Backdoor.MSIL.Bladabindi.bvtp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Bladabindi.bvtp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Deletes executed files from disk

How to determine Backdoor.MSIL.Bladabindi.bvtp?


File Info:

name: AF2A34CA1DDAE0DE3F44.mlw
path: /opt/CAPEv2/storage/binaries/203351da6970481678e520c7a75191ada675ce2199acd9e03459b24b5feee985
crc32: 3047A283
md5: af2a34ca1ddae0de3f44cbce1f429df5
sha1: 46ed654d64b331ccd23683b00cdb93d1098b9e12
sha256: 203351da6970481678e520c7a75191ada675ce2199acd9e03459b24b5feee985
sha512: f72a11517e414e3004871369d525d931a11c576ee4e471da6d570995ae450f9509f6fdbb5e6f213a121b542502e19490780f9dad5aa96d29f1fce03dee045a7c
ssdeep: 24576:arn7UxQK520adzmG61/g9WUnkKCvPlxycOl10/oFjo03PNCF4R1jX+4FhpJHZ0Ai:aM75rap/YWq0X3PYUhTpUAkiXa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEA523611A25EA81D7442F322EB11CE412465DFECAFEE9700BE937BF157F93422461A3
sha3_384: b34e070527c2b5da7a574f03764ccc6cce8769f793f854e9262d1f98f41114b12e048c8bfa83752c11eb1a37b7230a63
ep_bytes: e8063020006a00ff15a4606000c34200
timestamp: 2022-09-05 13:13:22

Version Info:

0: [No Data]

Backdoor.MSIL.Bladabindi.bvtp also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.ExNuma.1
FireEyeGeneric.mg.af2a34ca1ddae0de
ALYacGen:Variant.ExNuma.1
CylanceUnsafe
VIPREGen:Variant.ExNuma.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058ee541 )
K7GWTrojan ( 0058ee541 )
Cybereasonmalicious.a1ddae
CyrenW32/ExNuma.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HNPY
APEXMalicious
KasperskyBackdoor.MSIL.Bladabindi.bvtp
BitDefenderGen:Variant.ExNuma.1
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.zad
Ad-AwareGen:Variant.ExNuma.1
DrWebTrojan.MulDrop20.51329
McAfee-GW-EditionBehavesLike.Win32.VirRansom.vh
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.QuasarRAT.B
AviraHEUR/AGEN.1215601
MicrosoftVirTool:Win32/Pucrpt.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R442079
McAfeeGenericRXSN-KL!AF2A34CA1DDA
MAXmalware (ai score=82)
VBA32BScope.TrojanSpy.Stealer
RisingBackdoor.Crysan!8.10ECA (TFE:2:16hue2QNSkM)
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HNPY!tr
BitDefenderThetaAI:Packer.879E8DBE1E
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.MSIL.Bladabindi.bvtp?

Backdoor.MSIL.Bladabindi.bvtp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment