Malware

Should I remove “Generic.MSIL.Bladabindi.7422E91B”?

Malware Removal

The Generic.MSIL.Bladabindi.7422E91B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.7422E91B virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the Njrat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.MSIL.Bladabindi.7422E91B?


File Info:

name: 024B6DD162938C13A804.mlw
path: /opt/CAPEv2/storage/binaries/03c97053b9338f3ae967156ff976d752248a29b749b5f1d650713fad56367449
crc32: 9D53704F
md5: 024b6dd162938c13a8044b7081a6dcce
sha1: 35f6e676499215833d50c1e96caf1c2814362b88
sha256: 03c97053b9338f3ae967156ff976d752248a29b749b5f1d650713fad56367449
sha512: 683f46ba586641fa59399c615066fe3e9ce4ace8a3595e821f2606ffca8871990360173839f2f30ac2371770895751738c9ea93c4e4dbfbba092a5454165ae75
ssdeep: 384:RtqyOgLkFPWzaxVEfkxNqH06lgxeVN2R4cxKFONxVOzlYm4lVMssomjGuTM8tEFs:bZ0VKfjU4VFOrnrSVdtE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135B2198D3BACC996C9BC177496B9971003F491870022EE2A9CD990DFBF376C92D487E5
sha3_384: 81c95411fdd4825bed0a6ebda48be7a200890575e24070af66f69f63fe8c44a8631b73004d746577faeb3a1e88522f30
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-08-01 14:37:27

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.7422E91B also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.mAmC
ElasticWindows.Trojan.Njrat
MicroWorld-eScanGeneric.MSIL.Bladabindi.7422E91B
FireEyeGeneric.mg.024b6dd162938c13
CAT-QuickHealBackdoor.Bladabindi.AJ6
McAfeeTrojan-FIGN
Cylanceunsafe
VIPREGeneric.MSIL.Bladabindi.7422E91B
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0053ae0e1 )
K7AntiVirusTrojan ( 0053ae0e1 )
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Bladabindi.BOQ
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.7422E91B
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentTrojan.Msil.Bladabindi.za
SophosTroj/Bbindi-W
DrWebBackDoor.Bladabindi.13678
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.mm
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.Bladabindi.7422E91B (B)
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojan/Generic.bhxwv
GoogleDetected
AviraTR/Dropper.Gen7
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
XcitiumTrojWare.MSIL.Bladabindi.C@57iw6e
ArcabitGeneric.MSIL.Bladabindi.7422E91B
ViRobotBackdoor.Win32.Bladabindi.Gen.A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bladabindi.C952832
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36308.bmW@aShyVPi
MAXmalware (ai score=83)
VBA32Trojan.MSIL.Bladabindi.Heur
MalwarebytesBackdoor.NJRat.Generic
TrendMicro-HouseCallBKDR_BLADABI.SMI
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-DRD [Trj]
PandaTrj/CI.A

How to remove Generic.MSIL.Bladabindi.7422E91B?

Generic.MSIL.Bladabindi.7422E91B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment