Malware

How to remove “Generic.MSIL.Bladabindi.91CBFC2B”?

Malware Removal

The Generic.MSIL.Bladabindi.91CBFC2B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.91CBFC2B virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.91CBFC2B?


File Info:

name: AD3E751175E0DC21659A.mlw
path: /opt/CAPEv2/storage/binaries/48f9eae8ca2e1413f563df1124c572785e7817fcfad6b238fbfaac9dde8c4470
crc32: 1D84A07B
md5: ad3e751175e0dc21659ac0560ffa565b
sha1: 0a25048befce3c698ad9fd86243089bed531a69d
sha256: 48f9eae8ca2e1413f563df1124c572785e7817fcfad6b238fbfaac9dde8c4470
sha512: a61f7d6055366e9b343dba5e7b3d86a9b5562a5c923d12c23ba9288ceb7c3000ef20b8289e355078bfe20abe2f06cb3ff5e0b8f11896605fbc5acf7aad870b83
ssdeep: 384:ESItl77FDFucYfKQCcHN5vljmOmqDIlXHeHNGBsbh0w4wlAokw9OhgOL1vYRGOZO:m77ucYfKQTtzjAqc3eUBKh0p29SgR9U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18FD209193BB84926C4BC1B74C431961746F486032553DFAFDDD1A8DA9EE72E42A0CBF1
sha3_384: 57998c4170bacb1db353ab8506096da7e65f7ec8395da8bc386ecf8f4de45c137b0d806b5ec9eef22aedb966528a92b6
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-05-27 10:17:54

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.91CBFC2B also known as:

BkavW32.AIDetectNet.01
ElasticWindows.Trojan.Njrat
DrWebTrojan.DownLoader19.28708
MicroWorld-eScanGeneric.MSIL.Bladabindi.91CBFC2B
FireEyeGeneric.mg.ad3e751175e0dc21
CAT-QuickHealTrojan.Bladabindi.B3
ALYacGeneric.MSIL.Bladabindi.91CBFC2B
MalwarebytesBackdoor.Bladabindi.MSIL
VIPREGeneric.MSIL.Bladabindi.91CBFC2B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003ca8581 )
K7GWTrojan ( 003ca8581 )
Cybereasonmalicious.175e0d
BitDefenderThetaGen:NN.ZemsilF.34646.bmW@aSfbpsp
VirITTrojan.Win32.MSIL.AVDL
CyrenW32/MSIL_Bladabindi.A.gen!Eldorado
SymantecBackdoor.Ratenjay
tehtrisGeneric.Malware
ESET-NOD32MSIL/Bladabindi.F
APEXMalicious
ClamAVWin.Packed.Bladabindi-7086597-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.91CBFC2B
NANO-AntivirusTrojan.Win32.Dwn.dbxzfj
SUPERAntiSpywareTrojan.Agent/Gen-Barys
AvastMSIL:Agent-BXF [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGeneric.MSIL.Bladabindi.91CBFC2B
SophosML/PE-A + Troj/MSIL-HX
ComodoTrojWare.MSIL.Bladabindi.KX@52g0y5
F-SecureBackdoor.BDS/Bladabindi.bbyr
BaiduMSIL.Backdoor.Bladabindi.a
ZillyaTrojan.Bladabindi.Win32.14971
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.mm
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.Bladabindi.91CBFC2B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Autoit.dce
WebrootW32.Trojan.Gen
GoogleDetected
AviraBDS/Bladabindi.bbyr
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ArcabitGeneric.MSIL.Bladabindi.91CBFC2B
ViRobotBackdoor.Win32.Bladabindi.Gen.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Bladabindi.AV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bladabindi.C202658
Acronissuspicious
McAfeeTrojan-FIGN
CylanceUnsafe
TrendMicro-HouseCallBKDR_BLBINDI.SM
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.Agent!noyuSI5gvEg
IkarusTrojan.Msil
MaxSecureTrojan.MSIL.Agent.Rzr
FortinetMSIL/Agent.PPV!tr
AVGMSIL:Agent-BXF [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.MSIL.Bladabindi.91CBFC2B?

Generic.MSIL.Bladabindi.91CBFC2B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment