Malware

How to remove “Generic.MSIL.Bladabindi.EA7222AF”?

Malware Removal

The Generic.MSIL.Bladabindi.EA7222AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.EA7222AF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.EA7222AF?


File Info:

name: 8FBF3B8AF4B76697ABDA.mlw
path: /opt/CAPEv2/storage/binaries/5aeb8d1d7eb27f1b880ddeef9f60dd176f6d29ec636e7d8b87220a8717aa290c
crc32: B6ACB009
md5: 8fbf3b8af4b76697abda51e1a7e6f42c
sha1: 038442801daff79f0e3570454ac192dde9a2e34d
sha256: 5aeb8d1d7eb27f1b880ddeef9f60dd176f6d29ec636e7d8b87220a8717aa290c
sha512: 7ed33632f98e5c9ae620577d3bade5cd45c582df758878452065cc62b1866e26adeaa8ea8d2089c336c0e1dfac7e4a6d101d3c853aec26f651dfbc9ecb967e65
ssdeep: 3072:0TposMTJLW7lqiSfUENB+4c40gHDz5tXnonn3CA/0Nb:EposMTI7l49c40uDzLX1f1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FF37D38BFEC5481C1D85777B4DB45A1A2B0AA11BA43D79B306E15EA3EE23D81D0274F
sha3_384: d257a392f8aaa14575e19ca0c1843a0042d9d704394a192592c2ec9024a990fd7da5a25bda431dc1cc775c33ada761a8
ep_bytes: ff250000410009000000008c06004621
timestamp: 2022-07-07 01:04:58

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.EA7222AF also known as:

BkavW32.AIDetectNet.01
ElasticWindows.Trojan.Njrat
CynetMalicious (score: 100)
FireEyeGeneric.mg.8fbf3b8af4b76697
MalwarebytesBladabindi.Backdoor.Njrat.DDS
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGeneric.MSIL.Bladabindi.EA7222AF
K7GWTrojan ( 7000001c1 )
K7AntiVirusTrojan ( 7000001c1 )
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Bladabindi.LX
APEXMalicious
ClamAVWin.Trojan.B-468
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanGeneric.MSIL.Bladabindi.EA7222AF
AvastWin32:RATX-gen [Trj]
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.EA7222AF
EmsisoftGeneric.MSIL.Bladabindi.EA7222AF (B)
F-SecureHeuristic.HEUR/AGEN.1226402
VIPREGeneric.MSIL.Bladabindi.EA7222AF
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Bbindi-W
IkarusTrojan.MSIL.Bladabindi
GDataGeneric.MSIL.Bladabindi.EA7222AF
JiangminTrojanDropper.Autoit.dce
AviraHEUR/AGEN.1226402
ArcabitGeneric.MSIL.Bladabindi.EAD1C36AF
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.AJ
AhnLab-V3Trojan/Win32.RL_Generic.C4333872
Acronissuspicious
ALYacGeneric.MSIL.Bladabindi.EA7222AF
MAXmalware (ai score=88)
CylanceUnsafe
TencentTrojan.Win32.Bladabindi.16000442
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34786.kuW@a4Al5!k
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.af4b76

How to remove Generic.MSIL.Bladabindi.EA7222AF?

Generic.MSIL.Bladabindi.EA7222AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment