Malware

Generic.MSIL.Bladabindi.04F22B94 removal guide

Malware Removal

The Generic.MSIL.Bladabindi.04F22B94 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.04F22B94 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.04F22B94?


File Info:

name: 6494DE18039B09E88C96.mlw
path: /opt/CAPEv2/storage/binaries/8e6910dd2be1dda90c506f947549aa0ef56cdfdfbeafede28c98e6a47e06e6a1
crc32: 40784F67
md5: 6494de18039b09e88c96d44eaa227676
sha1: 96633364a8883b9aa1db6ba2af4ca6d107b9137e
sha256: 8e6910dd2be1dda90c506f947549aa0ef56cdfdfbeafede28c98e6a47e06e6a1
sha512: 4e8bbd533b0aa77da93eddb4780e8d92c30e914c71634dbe157ac029cd8f5a31aebba8606f031425c4cd3d8b76f6709e678cc896a6189c46102d61cc437c4013
ssdeep: 1536:lUk1GkeUqZJO5iNSimjEwzGi1dDvD+gS:lUPUqZJOQAOi1dfj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE93E84977E56524E1BF56F79471F2004E34B48B1602E39E48F219AA0B33AC44F89FEB
sha3_384: 52e59558be4d52e32b7aab717b43839916aa4524fb4bf9c1fe2e83cda784b9691dc5cc27ad716692b4c5ae5c239cf5c8
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-14 19:18:36

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.04F22B94 also known as:

BkavW32.PrimeaClefAF.Trojan
ElasticWindows.Trojan.Njrat
MicroWorld-eScanGeneric.MSIL.Bladabindi.04F22B94
ClamAVWin.Packed.Generic-9795615-0
FireEyeGeneric.mg.6494de18039b09e8
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.MSIL.Bladabindi.04F22B94
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00555f371 )
K7GWEmailWorm ( 00555f371 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.MulDrop7.DOQR
CyrenW32/Trojan.BVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.R
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.04F22B94
NANO-AntivirusTrojan.Win32.TrjGen.dkmeat
AvastWin32:KeyloggerX-gen [Trj]
TencentWorm.Msil.Agent.zo
Ad-AwareGeneric.MSIL.Bladabindi.04F22B94
TACHYONTrojan/W32.DN-Agent.95232.BC
EmsisoftWorm.Autorun (A)
DrWebTrojan.MulDrop7.62625
VIPREGeneric.MSIL.Bladabindi.04F22B94
TrendMicroBackdoor.MSIL.BLADABINDI.SMJJ
McAfee-GW-EditionBehavesLike.Win32.Backdoor.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/MsilPKill-C
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Agent.AXJ
AviraTR/Dropper.Gen
ArcabitGeneric.MSIL.Bladabindi.04F22B94
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.BN
GoogleDetected
AhnLab-V3Trojan/Win32.Bladabindi.R295982
Acronissuspicious
McAfeeTrojan-FIDH!6494DE18039B
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Bladabindi.Heur
MalwarebytesGeneric.Worm.Autorun.DDS
TrendMicro-HouseCallBackdoor.MSIL.BLADABINDI.SMJJ
RisingBackdoor.njRAT!1.A096 (CLASSIC)
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.LX!tr
BitDefenderThetaGen:NN.ZemsilF.34726.fiW@ai18@K
AVGWin32:KeyloggerX-gen [Trj]
Cybereasonmalicious.8039b0

How to remove Generic.MSIL.Bladabindi.04F22B94?

Generic.MSIL.Bladabindi.04F22B94 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment