Malware

Generic.MSIL.Bladabindi.6004D539 removal tips

Malware Removal

The Generic.MSIL.Bladabindi.6004D539 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.6004D539 virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the NjRATGolden malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.MSIL.Bladabindi.6004D539?


File Info:

name: BBF3E17B1AD82C3A652F.mlw
path: /opt/CAPEv2/storage/binaries/1786c0f069d3dc0020d181b767e9f79abbde8b6c1aff894853dbef9f44fdc4b4
crc32: 65306A76
md5: bbf3e17b1ad82c3a652f5242c576a0c1
sha1: 4fa5830c44f8fcb4ff17e6aab565d23c846f3585
sha256: 1786c0f069d3dc0020d181b767e9f79abbde8b6c1aff894853dbef9f44fdc4b4
sha512: ac9d340c65c51db69e8a79d1517ea7372e1bcc1b6f0998128f2405c68da42945a075721b441f9fa1de396e0dbec391635726544033974134873414f37cae60d4
ssdeep: 6144:bJZrdVtOCzUHl7wogBXYQtE+t+wATgxeXcy8B6Vm96/b2K7S:bJZrzg4UHl7woEIQKX58ows/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B54AE89EBE44DC2E46C033496BA58312F3B6D6E4E19674E258C705A3EB77832036F57
sha3_384: 6b64041ce861e1d9d336e060d00d1a99158a7dae0ea2ff77befd441f4c4ce1fb5f5450001298ce73301c01a8e8cfcadc
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-05-04 01:44:34

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.6004D539 also known as:

BkavW32.FamVT.binANHb.Worm
LionicTrojan.Win32.Generic.mAmC
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.MSIL.Bladabindi.6004D539
ClamAVWin.Packed.Generic-9795615-0
FireEyeGeneric.mg.bbf3e17b1ad82c3a
CAT-QuickHealTrojan.Generic.TRFH5
ALYacGeneric.MSIL.Bladabindi.6004D539
MalwarebytesGeneric.Malware.AI.DDS
SangforWorm.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:Win32/Bladabindi.374
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.G.gen!Eldorado
SymantecBackdoor.Ratenjay
ElasticWindows.Trojan.Njrat
ESET-NOD32MSIL/Bladabindi.AS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.6004D539
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
ViRobotBackdoor.Win32.Bladabindi.Gen.A
AvastMSIL:Agent-DRD [Trj]
TencentTrojan.Msil.Bladabindi.za
EmsisoftTrojan.Bladabindi (A)
F-SecureTrojan.TR/Dropper.Gen7
DrWebBackDoor.Bladabindi.13678
VIPREGeneric.MSIL.Bladabindi.6004D539
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosTroj/Bbindi-W
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
AviraTR/Dropper.Gen7
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
XcitiumBackdoor.MSIL.Bladabindi.A@566ygc
ArcabitGeneric.MSIL.Bladabindi.6004D539
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi
GoogleDetected
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=80)
VBA32Trojan.MSIL.Bladabindi.Heur
Cylanceunsafe
PandaTrj/CI.A
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
BitDefenderThetaAI:Packer.33B639F525
AVGMSIL:Agent-DRD [Trj]
Cybereasonmalicious.b1ad82
DeepInstinctMALICIOUS

How to remove Generic.MSIL.Bladabindi.6004D539?

Generic.MSIL.Bladabindi.6004D539 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment