Backdoor

Backdoor:MSIL/Bladabindi.G information

Malware Removal

The Backdoor:MSIL/Bladabindi.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Bladabindi.G virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Looks up the external IP address
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

checkip.dyndns.org

How to determine Backdoor:MSIL/Bladabindi.G?


File Info:

crc32: 2177BF85
md5: bb2a2e0d3a36c49e20da1f4c4ffc6751
name: ag.exe
sha1: 12e791ad017c04eb9f13e19df30c1a29aba4e31e
sha256: bb5f3d18f40469de7e206b825fdd8953fa97e3c1da2d447f1113201dd74c2526
sha512: c15083e4689feee480a3e453106fbf32fca6d6db27a61c28b7505b1b0b3c000256a0ca6cb08047596c7c0ebc05925b038bafde8eb16a80f3333783861239699f
ssdeep: 3072:5w0jefOfU2MgkH+LGP34omKerVUzeeDXbwa21DH9ua/aHyvZRspd2i/:5w0CfOfU8+bwv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: FEPPWHQBELWLDYGZBERTGTAMDZGCNBHHVQTAKLRX.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: FEPPWHQBELWLDYGZBERTGTAMDZGCNBHHVQTAKLRX.exe

Backdoor:MSIL/Bladabindi.G also known as:

MicroWorld-eScanGeneric.MSIL.PasswordStealerA.78E91272
FireEyeGeneric.mg.bb2a2e0d3a36c49e
CAT-QuickHealPUA.GenericFC.S7082425
McAfeeTrojan-FPEL!BB2A2E0D3A36
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGeneric.MSIL.PasswordStealerA.78E91272
K7GWTrojan ( 0052d5341 )
K7AntiVirusTrojan ( 0052d5341 )
TrendMicroTROJ_GEN.R002C0DBP20
F-ProtW32/MSIL_Troj.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Razy-6519812-0
GDataWin32.Malware.Bucaspys.A
KasperskyTrojan-Spy.MSIL.Agent.tfqt
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Agensla.hciyuo
ViRobotTrojan.Win32.Z.Spy.187392
RisingSpyware.AgentTesla!1.B864 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/MSIL-A
F-SecureTrojan.TR/Spy.Agent.lkofd
DrWebTrojan.PWS.Stealer.19347
Invinceaheuristic
McAfee-GW-EditionTrojan-FPEL!BB2A2E0D3A36
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.PasswordStealerA.78E91272 (B)
IkarusTrojan-Spy.Keylogger.AgentTesla
CyrenW32/MSIL_Troj.E.gen!Eldorado
WebrootW32.Trojan.Agent.Gen
AviraTR/Spy.Agent.lkofd
MAXmalware (ai score=82)
MicrosoftBackdoor:MSIL/Bladabindi.G
ArcabitGeneric.MSIL.PasswordStealerA.78E91272
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.a
AhnLab-V3Trojan/Win32.Bladabindi.C3246972
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.Bladabindi
Ad-AwareGeneric.MSIL.PasswordStealerA.78E91272
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.DF
TrendMicro-HouseCallTROJ_GEN.R002C0DBP20
TencentMsil.Trojan-spy.Agent.Pfje
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/MSIL.A!worm
BitDefenderThetaAI:Packer.FFA538D020
AVGMSIL:IELib-A [Trj]
Cybereasonmalicious.d3a36c
AvastMSIL:IELib-A [Trj]
Qihoo-360Generic/Trojan.Spy.0f3

How to remove Backdoor:MSIL/Bladabindi.G?

Backdoor:MSIL/Bladabindi.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment