Malware

Win32:GenMalicious-BDB [Trj] removal guide

Malware Removal

The Win32:GenMalicious-BDB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMalicious-BDB [Trj] virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

nikitahack.ddns.net

How to determine Win32:GenMalicious-BDB [Trj]?


File Info:

crc32: B3615F20
md5: 79ffe7bc9a93f541390aee0889a84eba
name: 79FFE7BC9A93F541390AEE0889A84EBA.mlw
sha1: f1252ad73b1b08ff53be5b8f5022a98982ba7230
sha256: e60c4be8e60b247c14021842a6543967b7ebd30992d12d634760ebf038773d6d
sha512: 349380aabbecec6e64cd39b04f38c835f81aa8315c6058169e5e43a78f7e80c3d2ffc65168e60714b560ced3ed8002cdf53441d8de7f36a8a0dd2296d32a34c3
ssdeep: 49152:SnmpXMc7abTTpZ5cIQ4ikHbG8FIx/re7ZI:UmpXbQCIviaG8F0/reS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa92014 BitTorrent, Inc. All Rights Reserved.
InternalName: uTorrent.exe
FileVersion: 3.4.2.34944
CompanyName: BitTorrent Inc.
SpecialBuild: stable34 stable
ProductName: xb5Torrent
ProductVersion: 3.4.2.34944
FileDescription: xb5Torrent
OriginalFilename: uTorrent.exe
Translation: 0x0409 0x04e4

Win32:GenMalicious-BDB [Trj] also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.Inject4.5168
MicroWorld-eScanGen:Trojan.Heur.AutoIT.12
FireEyeGeneric.mg.79ffe7bc9a93f541
CAT-QuickHealBackdoor.DarkKomet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.12
K7GWTrojan ( 700000111 )
Cybereasonmalicious.c9a93f
TrendMicroTROJ_GEN.R06EC0RKG20
BitDefenderThetaAI:Packer.39DE3CF819
CyrenW32/AutoIt.DN.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:GenMalicious-BDB [Trj]
ClamAVWin.Trojan.Autoit-9790251-0
KasperskyBackdoor.Win32.Poison.jnvu
AlibabaBackdoor:Win32/Poison.23016928
Ad-AwareGen:Trojan.Heur.AutoIT.12
SophosTroj/HkAutoIt-J
F-SecureDropper.DR/AutoIt.Gen
InvinceaTroj/HkAutoIt-J
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftGen:Trojan.Heur.AutoIT.12 (B)
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_90%
AviraDR/AutoIt.Gen
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Ymacco.AAE6
ArcabitTrojan.Heur.AutoIT.12
ZoneAlarmBackdoor.Win32.Poison.jnvu
GDataGen:Trojan.Heur.AutoIT.12
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Fynloski.R139779
McAfeeArtemis!79FFE7BC9A93
ESET-NOD32a variant of Win32/Injector.DMUI
TrendMicro-HouseCallTROJ_GEN.R06EC0RKG20
TencentMalware.Win32.Gencirc.11b130db
SentinelOneStatic AI – Malicious PE
FortinetW32/DMUI.J!tr
AVGWin32:GenMalicious-BDB [Trj]
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.9ae

How to remove Win32:GenMalicious-BDB [Trj]?

Win32:GenMalicious-BDB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment