Malware

Generic.Dacic.1.BitCoinMiner.A.467176FB (file analysis)

Malware Removal

The Generic.Dacic.1.BitCoinMiner.A.467176FB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.1.BitCoinMiner.A.467176FB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Generic.Dacic.1.BitCoinMiner.A.467176FB?


File Info:

name: 3EA9224A7959276E4CF7.mlw
path: /opt/CAPEv2/storage/binaries/b9b7b5721e3ff02a3273bfc99be2d4ebf7323eaace6ed1af8b0c67e0103f351a
crc32: 83011F7C
md5: 3ea9224a7959276e4cf72eaa1bd354b1
sha1: 76886e7602ae856b1d1b86f52ffd9cc3af58de40
sha256: b9b7b5721e3ff02a3273bfc99be2d4ebf7323eaace6ed1af8b0c67e0103f351a
sha512: 485f071e6a05102b3971801dd1f6fea74a3c9e5467bfed29f991e3a8682249de2f63aaf6729a6485a2298dcaea3e5a25a4ccc19150babf878492925b36cb229a
ssdeep: 49152:A7dXY+JCWrDIcr5jHnvwHARYXeoHKBgRNoKR+wtQN86aHaifLwGZ31Kk3rJ5GpBL:A7dXY+JCAZtjHnvMARMKBgRWy+wtQN81
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BE59D73048273D4EB987C784A6BAC5CF8546D84EF2BE679CC00F58684B6BD522E8C5D
sha3_384: c8a1eef950a50727c7417f0b600c5baa5cf1007db44226a46ed694abd68443a28011e62f47253d6a4732aa985fbb7031
ep_bytes: 558bec6aff68e07c410068e45b400064
timestamp: 2021-12-01 19:53:06

Version Info:

CompanyName:
FileDescription: Server MFC Application
FileVersion: 1, 0, 0, 1
InternalName: Server
LegalCopyright: Copyright (C) 2021
LegalTrademarks:
OriginalFilename: Server.EXE
ProductName: Server Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Generic.Dacic.1.BitCoinMiner.A.467176FB also known as:

LionicTrojan.Win32.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB
FireEyeGeneric.mg.3ea9224a7959276e
McAfeeArtemis!3EA9224A7959
CylanceUnsafe
SangforCoinMiner.Win32.Miner.gen
AlibabaTrojan:Win64/Miner.f94a1958
Cybereasonmalicious.a79592
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.FPBZJQB potentially unwanted
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win64.Miner.aqkn
BitDefenderDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB
AvastWin32:Malware-gen
TencentWin32.Trojan.Miner.Lnyn
Ad-AwareDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB
EmsisoftDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB (B)
ZillyaTrojan.Miner.Win32.15279
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA HG (PUA)
GDataDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB
AviraTR/CoinMiner.kdjno
Antiy-AVLTrojan/Generic.ASMalwS.34FB9C9
ViRobotTrojan.Win32.Z.Wacapew.3104768
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 99)
VBA32BScope.Trojan.AntiAV
ALYacDeepScan:Generic.Dacic.1.BitCoinMiner.A.467176FB
MAXmalware (ai score=83)
MalwarebytesPUP.Optional.ChinAd
TrendMicro-HouseCallTROJ_GEN.R06CH07L721
RisingHackTool.VulnDriver/x64!1.D7DB (CLOUD)
eGambitUnsafe.AI_Score_97%
FortinetRiskware/Application
AVGWin32:Malware-gen
PandaTrj/RnkBendM.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.Dacic.1.BitCoinMiner.A.467176FB?

Generic.Dacic.1.BitCoinMiner.A.467176FB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment