Malware

What is “Generic.Dacic.467A5BC0.A.E9ACA8DC”?

Malware Removal

The Generic.Dacic.467A5BC0.A.E9ACA8DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.467A5BC0.A.E9ACA8DC virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects VMware through the presence of a file
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.467A5BC0.A.E9ACA8DC?


File Info:

name: D5001EDE795248172CD9.mlw
path: /opt/CAPEv2/storage/binaries/9fda0ca05dae9b734289209cb4e8c74c2d1d0b164d59c294e3d1dbffeb386878
crc32: B42F7B0E
md5: d5001ede795248172cd941f495baad64
sha1: 9d643655894299130b16056c0c3385329592514e
sha256: 9fda0ca05dae9b734289209cb4e8c74c2d1d0b164d59c294e3d1dbffeb386878
sha512: aa51a2684fca7df6df8173459c593a464fdc0d95a2254d4e73266b34ed36e02cacecd815c32d9fa0f34615d19051e0f201f6644c0bd934066d105c3a3ccb344b
ssdeep: 6144:7flfAviLxlIJjiJcbI03GBc3ucY5DCSjX:7flfAviWGjSGecvX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0747C04BAA4F0F6DD95043804EBAF36967EB4281726CBC7E354CE5D99113C3A9346AF
sha3_384: 217abb32addbc958889115ec7f3ce8e35909b4e6674ad43f942ed86d729db8c59922e7cb27c42c3dd9f7249e61d21fa0
ep_bytes: e8692f0000e979feffff8bff558bec81
timestamp: 2012-07-12 02:56:49

Version Info:

FileDescription: ....................请点击允许,拒绝将无法使用!!!!!!!!!!!!!!!!!!!!!!!!!!!
FileVersion: 1, 0, 0, 1
InternalName: help
LegalCopyright: Copyright (C) 2012
OriginalFilename: no
ProductName: 辅助 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Generic.Dacic.467A5BC0.A.E9ACA8DC also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Click2.32800
MicroWorld-eScanGeneric.Dacic.467A5BC0.A.E9ACA8DC
FireEyeGeneric.mg.d5001ede79524817
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXAC-YK!D5001EDE7952
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.467A5BC0.A.E9ACA8DC
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005565241 )
K7GWTrojan ( 005565241 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36318.wy0@aKaLIQjj
CyrenW32/Pleh.A.gen!Eldorado
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.PGA
APEXMalicious
ClamAVWin.Malware.Mikey-9949492-0
KasperskyVHO:Backdoor.Win32.Zegost.gen
BitDefenderGeneric.Dacic.467A5BC0.A.E9ACA8DC
NANO-AntivirusTrojan.Win32.Invader.vxfyv
AvastWin32:Agent-AUSD [Rtk]
TencentTrojan.Win32.Nthook.a
TACHYONBackdoor/W32.Zegost.370176.B
EmsisoftGeneric.Dacic.467A5BC0.A.E9ACA8DC (B)
F-SecureTrojan.TR/Rogue.7909438
BaiduWin32.Rootkit.Agent.w
ZillyaTrojan.Tiny.Win32.20684
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.YSVY3N
JiangminTrojan/Invader.gje
GoogleDetected
AviraTR/Rogue.7909438
Antiy-AVLTrojan[Dropper]/Win32.Daws.aumx
XcitiumTrojWare.Win32.Clicker.naf@4qkqfk
ArcabitGeneric.Dacic.467A5BC0.A.E9ACA8DC
ZoneAlarmTrojan.Win32.Tiny.cm
MicrosoftTrojanDropper:Win32/Systex.A
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.YK.C5284538
VBA32Trojan.Tiny
ALYacGeneric.Dacic.467A5BC0.A.E9ACA8DC
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.83500
RisingTrojan.Agent!1.C16F (CLASSIC)
YandexTrojan.GenAsa!fCPsWhzUnE4
IkarusTrojan.SuspectCRC
MaxSecureDropper.Daws.aumx
FortinetW32/Wacatac.B!tr
AVGWin32:Agent-AUSD [Rtk]
DeepInstinctMALICIOUS

How to remove Generic.Dacic.467A5BC0.A.E9ACA8DC?

Generic.Dacic.467A5BC0.A.E9ACA8DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment