Malware

Troj/Bladabi-YB removal

Malware Removal

The Troj/Bladabi-YB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Bladabi-YB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Troj/Bladabi-YB?


File Info:

crc32: 3374081B
md5: b874427f06ee3cbce86d23cfdbf5c613
name: viromenbvlove.exe
sha1: f85cbd8f1f37f5217f2814c802b80f5343e125dd
sha256: 7ea7fdcd10b1630dcdd02e1ac446606ddc419a7e3255de7386542ce7134d18f2
sha512: 0fe9ccc6f5ff63675f652a45bf57e65dc2c28ef1bd2b3bd9eb5b8e8de030a3846ebb25291c04f40fabc03977d2c903026b2e7408e47e435916366dfd9425ed46
ssdeep: 12288:Aq69WpBG04JI9rbi6BVIWYS7iAXV2dtiLl:AqTnG0LbiK+XSeAXV2j
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2007
Assembly Version: 0.0.0.0
InternalName: ViromenBvlove.exe
FileVersion: 4.7.9.11
CompanyName: XJAXJ
Comments: FRA
ProductName: JXFQQCIB
ProductVersion: 4.7.9.11
FileDescription: JXFQQCIB
OriginalFilename: ViromenBvlove.exe

Troj/Bladabi-YB also known as:

MicroWorld-eScanTrojan.GenericKD.32782473
FireEyeGeneric.mg.b874427f06ee3cbc
CAT-QuickHealTrojan.MSIL
Qihoo-360HEUR/QVM03.0.7857.Malware.Gen
ALYacTrojan.Agent.Wacatac
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00555e3b1 )
BitDefenderTrojan.GenericKD.32782473
K7GWTrojan ( 00555e3b1 )
Cybereasonmalicious.f1f37f
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34090.Qm0@amgwaGo
CyrenW32/MSIL_Kryptik.NA.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.SMR
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32782473
KasperskyHEUR:Trojan.MSIL.Scarsi.gen
AlibabaTrojan:Win32/Malmail.ali1000112
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.32782473
EmsisoftTrojan.GenericKD.32782473 (B)
ComodoMalware@#3tljcrg8f7ow7
F-SecureTrojan.TR/Dropper.MSIL.odbae
DrWebTrojan.PWS.Siggen2.32905
ZillyaTrojan.Kryptik.Win32.1788615
TrendMicroTrojanSpy.MSIL.NEGASTEAL.KDM
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosTroj/Bladabi-YB
IkarusTrojan.MSIL.Crypt
WebrootW32.Trojan.Gen
AviraTR/Dropper.MSIL.odbae
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F43889
AhnLab-V3Malware/Win32.RL_Generic.C3450201
ZoneAlarmHEUR:Trojan.MSIL.Scarsi.gen
MicrosoftTrojan:Win32/Skeeyah.HK!MTB
Acronissuspicious
McAfeeGenericRXIL-CZ!B874427F06EE
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.RMCrypt.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.KDM
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Scarsi!DsVSMy6nUEw
SentinelOneDFI – Malicious PE
FortinetMSIL/Injector.UMM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.73692792.susgen

How to remove Troj/Bladabi-YB?

Troj/Bladabi-YB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment