Backdoor

Should I remove “Backdoor:MSIL/Gensteal.A”?

Malware Removal

The Backdoor:MSIL/Gensteal.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Gensteal.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup

How to determine Backdoor:MSIL/Gensteal.A?


File Info:

name: 461B1914643247DFFA51.mlw
path: /opt/CAPEv2/storage/binaries/632616bd2d2b0056d4010a0740bd1b719f00f114144a462cb1ec8e296d7556f1
crc32: D2EE8E16
md5: 461b1914643247dffa515c02a63499f3
sha1: 34bbbe90e17d9b561d42bab77910b64a8696f8ee
sha256: 632616bd2d2b0056d4010a0740bd1b719f00f114144a462cb1ec8e296d7556f1
sha512: 74597b6178e253392a9b2123d0133086b56fbdfb74551034abcdc87b099891adb58276cfb6116b36b3b0ab7e1b78a6f3e801426fbfa9bb736b35038c2904824b
ssdeep: 3072:jNh2I82iyxrCxzSMbP6s+iCIaEuBKa+ceVlpduPIjDQk5mGrZaGJ/XxsTAhc6EcC:fDxVs4EuBv+5TqgjDQknrU0/xsTF6Ef
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D34EF6C63AC6F27D3ED08FAC4E373200331957B4B4BF34F54441A724A697E6A462A5B
sha3_384: 7a73ca9c9a7bf8783b8b1eaa02d65a2a103ebf81ff344545131441c0383220694db572dc32bdbe75e96b95b41113f302
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-08 11:50:14

Version Info:

0: [No Data]

Backdoor:MSIL/Gensteal.A also known as:

LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.461b1914643247df
McAfeeArtemis!461B19146432
CylanceUnsafe
SangforBackdoor.MSIL.Bladabindi.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabindi.f729766b
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
CyrenW32/Trojan.FFV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.FRL
APEXMalicious
ClamAVWin.Packed.Disfa-7086490-0
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Heur.MSIL.Bladabindi.1
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
AvastMSIL:Agent-AQC [Trj]
TencentMsil.Backdoor.Bladabindi.Palv
Ad-AwareGen:Heur.MSIL.Bladabindi.1
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
DrWebTrojan.MulDrop19.23473
TrendMicroTROJ_GEN.R014C0RAA22
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-R + Mal/MSIL-LY
IkarusTrojan.MSIL.Injector
GDataGen:Heur.MSIL.Bladabindi.1
AviraHEUR/AGEN.1124943
ViRobotTrojan.Win32.Z.Injector.237568.HFT
MicrosoftBackdoor:MSIL/Gensteal.A
AhnLab-V3Trojan/Win32.RL_Agent.C3468415
BitDefenderThetaGen:NN.ZemsilF.34114.om0@am8Z7h
MAXmalware (ai score=87)
MalwarebytesTrojan.Agent.PGen
TrendMicro-HouseCallTROJ_GEN.R014C0RAA22
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:BgaBYLcp5wevooK53YPwrA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/FRL!tr
AVGMSIL:Agent-AQC [Trj]
Cybereasonmalicious.464324
PandaTrj/GdSda.A

How to remove Backdoor:MSIL/Gensteal.A?

Backdoor:MSIL/Gensteal.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment