Malware

Generic.MSIL.Bladabindi.66638BED removal guide

Malware Removal

The Generic.MSIL.Bladabindi.66638BED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.66638BED virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the Njrat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.MSIL.Bladabindi.66638BED?


File Info:

name: 8BE1FF1C33F94C750D3A.mlw
path: /opt/CAPEv2/storage/binaries/df609c05e178afee433fd39106c0b487f9319731d174595a23a30170160e142d
crc32: 8EE9B4E9
md5: 8be1ff1c33f94c750d3abae04b5d0be6
sha1: 1e721e79644c15b79baf6a786cf1c57869f6bd72
sha256: df609c05e178afee433fd39106c0b487f9319731d174595a23a30170160e142d
sha512: 591c5716b4d3c3df4ac2e2cfa08190b8b999fcd47369b44ef1e55e56ba48b4a9a23eb8e61fab3c3e79b7509afa8781b4cf77df6f070a48aa248e0226463fdd77
ssdeep: 384:eYS9VSikmV0NVtv/Vey0bucvbdms28vsErAF+rMRTyN/0L+EcoinblneHQM3epzM:dgpO1VV0bucxml8LrM+rMRa8Nuozt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178F2294D7FE08568C5FE067B05B2D4130777E00B6E23DD0D8EE6A4AA37636D18F54AA2
sha3_384: d994484a141bd98be94e2bff532e4eabfcf8f3b631b0fd9b63971be95b8f5130b5eccc74cdd40a3090d783352da127db
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-01 11:00:56

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.66638BED also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
ElasticWindows.Trojan.Njrat
DrWebTrojan.DownLoader22.4850
MicroWorld-eScanGeneric.MSIL.Bladabindi.66638BED
FireEyeGeneric.mg.8be1ff1c33f94c75
CAT-QuickHealTrojan.GenericFC.S19436243
McAfeeTrojan-FIGN
MalwarebytesBackdoor.NJRat
ZillyaTrojan.Bladabindi.Win32.37127
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 700000121 )
Cybereasonmalicious.c33f94
ArcabitGeneric.MSIL.Bladabindi.D1044EBED
BitDefenderThetaGen:NN.ZemsilF.34754.ciW@aGQfzLf
VirITTrojan.Win32.DownLoader21.BPQW
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AR
ZonerTrojan.Win32.84773
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6417450-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.66638BED
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
Ad-AwareGeneric.MSIL.Bladabindi.66638BED
EmsisoftGeneric.MSIL.Bladabindi.66638BED (B)
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
BaiduMSIL.Backdoor.Bladabindi.a
VIPREGeneric.MSIL.Bladabindi.66638BED
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Bbindi-W
IkarusTrojan.MSIL.Bladabindi
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4927
MicrosoftTrojan:MSIL/njRAT.RDSA!MTB
GDataMSIL.Trojan-Spy.Bladabindi.BQ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Korat.R213361
Acronissuspicious
VBA32Downloader.MSIL.gen
ALYacGeneric.MSIL.Bladabindi.66638BED
MAXmalware (ai score=89)
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
PandaTrj/GdSda.A

How to remove Generic.MSIL.Bladabindi.66638BED?

Generic.MSIL.Bladabindi.66638BED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment