Backdoor

About “Backdoor.MSIL.Blakken” infection

Malware Removal

The Backdoor.MSIL.Blakken is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Blakken virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.MSIL.Blakken?


File Info:

crc32: 11CC3872
md5: d08412601dc64d6dc5e3945d550ad9a9
name: D08412601DC64D6DC5E3945D550AD9A9.mlw
sha1: 06cfbf0af5ab9edc688ce9ef6a8ccb41bf3b3533
sha256: c8f8510cba7bf3a1af68bd76428a0fcaaf0cce231d22c366d49926122a2fb439
sha512: c2b33626958fe94bc46cf8c01bbcbfaaec1c10072181db654376b380efe0eb5e583bd63bf7ab93dbfd1002eefb08369ddd02ee778bd668d68dac5f16fd8dff68
ssdeep: 12288:GUGfvdnLnDy165y8aaYYI/Oy6h5JFvbB39y+:GhdLDh5yngXJFvZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) 2014 szr2000
Assembly Version: 1.0.0.0
InternalName: ReaderWriterLock.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments: A Twitter library that made by visual basic
ProductName: FistTwit
ProductVersion: 1.0.0.0
FileDescription: FistTwit
OriginalFilename: ReaderWriterLock.exe

Backdoor.MSIL.Blakken also known as:

K7AntiVirusTrojan ( 0057d2341 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.763
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0057d2341 )
Cybereasonmalicious.af5ab9
CyrenW32/MSIL_Troj.AXZ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABDO
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Backdoor.MSIL.Blakken.gen
BitDefenderTrojan.GenericKDZ.75508
MicroWorld-eScanTrojan.GenericKDZ.75508
Ad-AwareTrojan.GenericKDZ.75508
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.d08412601dc64d6d
EmsisoftTrojan.GenericKDZ.75508 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.tmiht
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.BBR!MTB
ArcabitTrojan.Bulz.D7821A
AegisLabTrojan.MSIL.Agensla.i!c
GDataMSIL.Trojan-Stealer.AgentTesla.CNE5QH
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=89)
MalwarebytesSpyware.LokiBot
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CER21
RisingBackdoor.Blakken!8.2E8C (CLOUD)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ABDO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Backdoor.MSIL.Blakken?

Backdoor.MSIL.Blakken removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment