Malware

Generic.MSIL.DownloaderB.5A11CD3E removal tips

Malware Removal

The Generic.MSIL.DownloaderB.5A11CD3E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.DownloaderB.5A11CD3E virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Generic.MSIL.DownloaderB.5A11CD3E?


File Info:

name: 6AD8A4A699C1891D1823.mlw
path: /opt/CAPEv2/storage/binaries/c19501fa90861d745550fc441ab0be3e4b4666cd5311bc8d6e199e5ab979885d
crc32: 24884790
md5: 6ad8a4a699c1891d18238d5ce55d2830
sha1: 869d1da6bf287168b3d437e830af53286c1ab1d2
sha256: c19501fa90861d745550fc441ab0be3e4b4666cd5311bc8d6e199e5ab979885d
sha512: be01f15da73b0a1051d6eb48a28cb5090557ed4c37977b72402ec3a2f1cfa8ad8fd995b5b88d42e9c495c9b3861609385270910943c4bbc196dda649e7bee505
ssdeep: 3072:NRSQKEYFxarwIJ74aaccmVahycZRzryuo1lnTqZkg+aAL:CQeEw0kcfVJczryuo7TqrA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDE3121A63DB91B1ECAC4770099B584175B3F21C471BFF6FABA294208E637D18727B11
sha3_384: b7fb9a3ec4a240e859a8a10670f91bdde0080a11d545b0a04754650a57df7c8ff54fad19b964bd8cc50b8c0d0522df4e
ep_bytes: ff250020400000000000000000000000
timestamp: 2059-07-03 21:15:11

Version Info:

Translation: 0x0000 0x04b0
Comments: NVIDIA Container
CompanyName: NVIDIA Container
FileDescription: NVIDIA Container
FileVersion: 1.0.0.0
InternalName: newfair.exe
LegalCopyright: Copyright © 2022
LegalTrademarks: NVIDIA Container
OriginalFilename: newfair.exe
ProductName: NVIDIA Container
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Generic.MSIL.DownloaderB.5A11CD3E also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGeneric.MSIL.DownloaderB.5A11CD3E
FireEyeGeneric.mg.6ad8a4a699c1891d
ALYacGeneric.MSIL.DownloaderB.5A11CD3E
K7AntiVirusTrojan-Downloader ( 005789081 )
K7GWTrojan-Downloader ( 005789081 )
Cybereasonmalicious.699c18
SymantecMSIL.Downloader!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HJI
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGeneric.MSIL.DownloaderB.5A11CD3E
AvastWin32:RATX-gen [Trj]
Ad-AwareGeneric.MSIL.DownloaderB.5A11CD3E
SophosMal/Generic-S
DrWebTrojan.DownLoader45.4767
VIPREGeneric.MSIL.DownloaderB.5A11CD3E
McAfee-GW-EditionArtemis
EmsisoftGeneric.MSIL.DownloaderB.5A11CD3E (B)
SentinelOneStatic AI – Malicious PE
GDataGeneric.MSIL.DownloaderB.5A11CD3E
AviraTR/Dldr.Agent.ofvon
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!6AD8A4A699C1
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:amIiv/wFge0lGHv07/Rmbw)
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.HJI!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34786.jm0@aWVr5V
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Generic.MSIL.DownloaderB.5A11CD3E?

Generic.MSIL.DownloaderB.5A11CD3E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment