Backdoor

Backdoor:MSIL/Bladabhindi.J!MTB (file analysis)

Malware Removal

The Backdoor:MSIL/Bladabhindi.J!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Bladabhindi.J!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory

Related domains:

mydocuments1.is

How to determine Backdoor:MSIL/Bladabhindi.J!MTB?


File Info:

crc32: C6789278
md5: 0c940ff05deeaf8f0838f1031b607a85
name: 0C940FF05DEEAF8F0838F1031B607A85.mlw
sha1: 67bef4918d3dd4658b6a03338e16179f30909e45
sha256: 23875e713f34d9e723e3727acae23e9539d86bb31af18cb3164f131b0f3836f5
sha512: 87cdee036faeb86fef63aaa2518701657ef4fde2b5ab064393179ea0f35d14f160758dbf9c63d08304fefcce4214e71cf6db2f518348c48ed0331daadc38f231
ssdeep: 12288:Mo17pY9aV0BiH9mLikXd2TFQZArR7AOwZuUzYcZ7zBCXmgHFr+JJcl/PWOI0PPW:eIVWiELiDyL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2011
Assembly Version: 1.0.0.0
InternalName: 98765.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: 98765.exe

Backdoor:MSIL/Bladabhindi.J!MTB also known as:

K7AntiVirusTrojan-Downloader ( 0053a87f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.6.Gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabhindi.67e3a993
K7GWTrojan-Downloader ( 0053a87f1 )
Cybereasonmalicious.05deea
CyrenW32/MSIL_Agent.BF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.EUH
APEXMalicious
AvastMSIL:GenMalicious-BBY [Trj]
ClamAVWin.Trojan.Agent-6645269-0
KasperskyHEUR:Backdoor.Win32.Agent.gen
BitDefenderTrojan.MSIL.Basic.6.Gen
NANO-AntivirusTrojan.Win32.MSILPerseus.fidbnf
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
TencentMsil.Trojan-downloader.Agent.Hyy
Ad-AwareTrojan.MSIL.Basic.6.Gen
SophosMal/Generic-S
ComodoMalware@#3rdax8qik83jw
BitDefenderThetaGen:NN.ZemsilF.34294.Hm0@aKihtpi
McAfee-GW-EditionGenericRXGL-IQ!0C940FF05DEE
FireEyeGeneric.mg.0c940ff05deeaf8f
EmsisoftTrojan-Downloader.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Agent.hzj
AviraHEUR/AGEN.1130323
Antiy-AVLTrojan/Generic.ASMalwS.276E429
MicrosoftBackdoor:MSIL/Bladabhindi.J!MTB
ArcabitTrojan.MSIL.Basic.6.Gen
GDataTrojan.MSIL.Basic.6.Gen
AhnLab-V3Trojan/Win32.Skeeyah.C2664279
McAfeeGenericRXGL-IQ!0C940FF05DEE
MAXmalware (ai score=99)
VBA32CIL.StupidPInvoker-2.Heur
MalwarebytesMalware.AI.2642262846
PandaTrj/GdSda.A
YandexTrojan.DL.Agent!Dng4sTMzBo8
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.CFC031C!tr
AVGMSIL:GenMalicious-BBY [Trj]
Paloaltogeneric.ml

How to remove Backdoor:MSIL/Bladabhindi.J!MTB?

Backdoor:MSIL/Bladabhindi.J!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment