Malware

What is “Generic.Dacic.49348E91.A.BFC5257C”?

Malware Removal

The Generic.Dacic.49348E91.A.BFC5257C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.49348E91.A.BFC5257C virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.49348E91.A.BFC5257C?


File Info:

name: F003C1EA37BF9C766508.mlw
path: /opt/CAPEv2/storage/binaries/c3eb06f8e0885d94fd5358f506f5ad05fadb5535e24541b630a7a3aface59633
crc32: AECEB537
md5: f003c1ea37bf9c7665081633096ca448
sha1: 1140f8013a2eff1bad3f9a3e02ae7a588fbcc6bb
sha256: c3eb06f8e0885d94fd5358f506f5ad05fadb5535e24541b630a7a3aface59633
sha512: 86db612f5f4d6dfac1468bd3b7d1f252d0d7c8852abd7a729d233c0a2fed4a07871cacbc25b413157f20f1eba3a6e16d201c83f06aa6c40fbd077472e6197b8a
ssdeep: 6144:Eh3rzMYXh+02d1r5ZTYnSbc0AJANv4hituxp38u0:OrgQmd195KS400ANv4h8u/8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177A5AF367BC0D0F1C0A2803123997E359DF6A8321322A567DF649A052AF56F5E73B74B
sha3_384: 8b9c90e5c6f38114d5907613e8fdb448a4ff4ef31244e33071a3ba5edbf66eafa89d7807beaae7547df360e3538eed02
ep_bytes: 6a606898974200e896f7ffffbf940000
timestamp: 2006-12-09 03:03:07

Version Info:

0: [No Data]

Generic.Dacic.49348E91.A.BFC5257C also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGeneric.Dacic.49348E91.A.BFC5257C
CAT-QuickHealWorm.Pykspa.C3
ALYacGeneric.Dacic.49348E91.A.BFC5257C
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.49348E91.A.BFC5257C
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.a37bf9
BitDefenderThetaGen:NN.ZexaF.36318.doW@aqHwxYh
CyrenW32/Pykspa.A.gen!Eldorado
SymantecW32.Pykspa.D
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.Agent.TG
APEXMalicious
ClamAVWin.Worm.Pykspa-9869413-0
KasperskyHEUR:Worm.Win32.Agent.gen
BitDefenderGeneric.Dacic.49348E91.A.BFC5257C
NANO-AntivirusTrojan.Win32.Vilsel.bqgox
ViRobotTrojan.Win32.A.Chydo.315392.B
AvastWin32:Renos-KY [Trj]
TencentTrojan.Win32.Chydo.xa
EmsisoftGeneric.Dacic.49348E91.A.BFC5257C (B)
BaiduWin32.Worm.Autorun.o
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Kypes
ZillyaTrojan.Vilsel.Win32.1428
TrendMicroWORM_PYKSPA_EI020005.UVPM
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f003c1ea37bf9c76
SophosW32/Koobfa-O
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11ROU0P
JiangminTrojan/Vilsel.bgc
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLWorm[IM]/Win32.Chydo.clr
XcitiumWorm.Win32.Autorun.Agent_TG1@1isixd
ArcabitGeneric.Dacic.49348E91.A.BFC5257C
ZoneAlarmHEUR:Worm.Win32.Agent.gen
MicrosoftWorm:Win32/Pykspa.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
McAfeeW32/Pykse.worm.gen.a
VBA32BScope.Trojan.Vilsel
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_PYKSPA_EI020005.UVPM
RisingWorm.Pykspa!1.A60D (CLASSIC)
YandexTrojan.GenAsa!oyWE4y6VTTI
IkarusWorm.Win32.Pykspa
FortinetW32/Pykse.F!tr
AVGWin32:Renos-KY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Dacic.49348E91.A.BFC5257C?

Generic.Dacic.49348E91.A.BFC5257C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment