Malware

Should I remove “Generic.MSIL.Bladabindi.BBA4B5CF”?

Malware Removal

The Generic.MSIL.Bladabindi.BBA4B5CF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.BBA4B5CF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.BBA4B5CF?


File Info:

name: 9F1AEA3D0AEF8C32D633.mlw
path: /opt/CAPEv2/storage/binaries/a19e362b8c6a8a5c95771c243edb1dc0cdedb49a4797dbcdae6021ca07ca923f
crc32: 46705375
md5: 9f1aea3d0aef8c32d633e33a61cac9cf
sha1: aed8809fe0a4d777742f452cb16c58f363b2b272
sha256: a19e362b8c6a8a5c95771c243edb1dc0cdedb49a4797dbcdae6021ca07ca923f
sha512: 71c36cad4d92a0ac3b192a5717a22ff5b35a5b011814f5e196f1f74f3aa4aa7600db6577f2830b153bc7f41b7360816537d657d1df1648fb81bf9685c474d950
ssdeep: 384:G38aZYC9twBNdcvFaly2H0dbJo6HghcASEJqc/ZmRvR6JZlbw8hqIusZzZ9+U:G7Y+sNKqNHnSdRpcnunU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEB21A4E3FA98856C5BD07708AA5969003B491470423EE2FCDC550DBAFB3BD92D4CAF9
sha3_384: 9c1b0f47532b67dc3aa9270b103f916827815776c4954512874db96b1f869f2ac9fcfb84d8c8762d15fe5e6cef5110b9
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-05 23:10:41

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.BBA4B5CF also known as:

BkavW32.FamVT.binANHb.Worm
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
MicroWorld-eScanGeneric.MSIL.Bladabindi.BBA4B5CF
FireEyeGeneric.mg.9f1aea3d0aef8c32
CAT-QuickHealTrojan.Generic.TRFH5
McAfeeTrojan-FIGN
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.55242
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:Win32/Bladabindi.374
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d0aef8
BitDefenderThetaGen:NN.ZemsilF.34182.bmW@aW8tTao
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.BH
TrendMicro-HouseCallBKDR_BLADABI.SMC
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyBackdoor.MSIL.Agent.jdt
BitDefenderGeneric.MSIL.Bladabindi.BBA4B5CF
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentMsil.Backdoor.Agent.Hupm
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
F-SecureTrojan.TR/Dropper.Gen7
BaiduMSIL.Backdoor.Bladabindi.a
VIPREBackdoor.MSIL.Bladabindi.a (v)
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/DotNet-P
IkarusTrojan.MSIL.Bladabindi
JiangminTrojanDropper.Autoit.dce
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen7
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
KingsoftWin32.Hack.MSIL.j.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ViRobotBackdoor.Win32.Bladabindi.Gen.A
ZoneAlarmBackdoor.MSIL.Agent.jdt
GDataMSIL.Backdoor.Bladabindi.AV
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
ALYacGeneric.MSIL.Bladabindi.BBA4B5CF
VBA32Trojan.MSIL.Disfa
MalwarebytesBackdoor.NJRat
APEXMalicious
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexBackdoor.Agent!hMARJwcVWJY
MAXmalware (ai score=82)
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-DRD [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.Bladabindi.BBA4B5CF?

Generic.MSIL.Bladabindi.BBA4B5CF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment