Malware

Mal/Generic-R + Troj/Bladabi-GX removal

Malware Removal

The Mal/Generic-R + Troj/Bladabi-GX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Bladabi-GX virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Attempts to disable UAC

How to determine Mal/Generic-R + Troj/Bladabi-GX?


File Info:

name: 7EC269662BC1AA2FDE77.mlw
path: /opt/CAPEv2/storage/binaries/078c233d49316e16aaf89f139fe76ab34b470ded131e3fd7b7d18a6a54e9fbed
crc32: 3875E42A
md5: 7ec269662bc1aa2fde7753482b0c80ec
sha1: 0b688bba463b983f14b9918aa7e6cb469ba5c8d9
sha256: 078c233d49316e16aaf89f139fe76ab34b470ded131e3fd7b7d18a6a54e9fbed
sha512: 324d556949bb351dfebc3269a73401e4f28d8f155624b17a2cb52d78ed40bb51c91eff1b4e9595bb9b3f6ca61613674a4d592b7c1d6f4cf20b18d6aca1fab897
ssdeep: 1536:Sa1RvLMml6gSLEFCDq6XEc4SnadJcLCyFismn/eU3Jw9rCUSE5fgYEuFUAluP:im0XEFCDbEhQFihnmwS9rCUZaJjAlo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2B3E05477114157C96E56784A6382B203B08D0BA613DAAFEDE5F8DF0DB33908D12EEE
sha3_384: 5069e5f852c8f61dddbbc5428fa52ef3603b94f4c64dd2e61bf276534e0a1188ed3cb4ea44f8b927a00c7051f85ae075
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-07-13 20:20:30

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Bladabi-GX also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.lzR3
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.9
FireEyeGeneric.mg.7ec269662bc1aa2f
CAT-QuickHealBackdoor.Bladabindi.B3
ALYacGen:Heur.MSIL.Krypt.9
MalwarebytesTrojan.Agent
VIPREGen:Heur.MSIL.Krypt.9
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Heur.MSIL.Krypt.9
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.623F10C020
VirITTrojan.Win32.MSIL.AA
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecBackdoor.Ratenjay!gen1
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zapchast-135
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:MSIL/Bladabindi.6db5d916
NANO-AntivirusTrojan.Win32.Barys.cwyboh
CynetMalicious (score: 100)
RisingBackdoor.Bot!1.6675 (CLASSIC)
Ad-AwareGen:Heur.MSIL.Krypt.9
SophosMal/Generic-R + Troj/Bladabi-GX
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
DrWebTrojan.MulDrop6.8196
ZillyaTrojan.Agent.Win32.353517
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionW32/Worm-FHS!7EC269662BC1
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.MSIL.Krypt.9 (B)
JiangminTrojan.Generic.oiyq
WebrootW32.Rogue.Gen
AviraTR/Barys.S
Antiy-AVLTrojan/Generic.ASMalwS.24D
KingsoftWin32.Troj.Agent.x.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.B
GDataGen:Heur.MSIL.Krypt.9
GoogleDetected
AhnLab-V3Trojan/Win32.Zapchast.R31274
Acronissuspicious
McAfeeW32/Worm-FHS!7EC269662BC1
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_BLBINDI.SM
TencentTrojan.Win32.Bladabindi.16000442
YandexTrojan.Bladabindi!yFlQQthloaQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.MSIL.Bladabindi.b
FortinetMSIL/Agent.PPV!tr
AVGMSIL:Agent-PI [Trj]
Cybereasonmalicious.62bc1a
AvastMSIL:Agent-PI [Trj]

How to remove Mal/Generic-R + Troj/Bladabi-GX?

Mal/Generic-R + Troj/Bladabi-GX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment