Malware

Generic.Dacic.635FDBB5.A.2E7C3A9C removal

Malware Removal

The Generic.Dacic.635FDBB5.A.2E7C3A9C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.635FDBB5.A.2E7C3A9C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the MetaStealer malware family
  • Attempts to identify installed AV products by installation directory
  • Binary file triggered YARA rule
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.Dacic.635FDBB5.A.2E7C3A9C?


File Info:

name: 79D3F3BC314F23D21EFF.mlw
path: /opt/CAPEv2/storage/binaries/6cb1f82b85af9acb5c3a3ab994ab94180e3a1db4a597d1622bf49bc1a3de8750
crc32: 403D313C
md5: 79d3f3bc314f23d21eff857ab34ba573
sha1: 87a5707f57be5850cdddfa831089bb3a59414542
sha256: 6cb1f82b85af9acb5c3a3ab994ab94180e3a1db4a597d1622bf49bc1a3de8750
sha512: fbefacbbb89af15b084c2a394d928e6ceead098290b3b05ac77c0b5f354d6e2f24a83a23982619cf996a508a9b1b73be4cdf336c341202255b131cc849dca012
ssdeep: 6144:qQef0CTELmBcnOY5P3m88BtK3wxU9TlVS+iEC9cNYF8Vxa2zGhS/Gtdpk+OedhXe:qQCThxQ2PBsVZDD55KFAAdp5OL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17FB4022E786041B1D97BD8BDF8F79D53B7BC5C32122413B3D26012AA1FA2AE1356711B
sha3_384: dd53ec3311d1e448c6e7462fb31a0aa43877dee01637e34d362924b8d61e5702e66f0cb3c2c1744e73dff580d7626624
ep_bytes: e8173c0000e9a4feffff3b0d3cd94700
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: American Colla USA
FileDescription: American Colla USA Product
FileVersion: 945
InternalName: 2CWm9P89OkGr
LegalCopyright: © American Colla USA All rights reserved.
LegalTrademarks: © American Colla USA Trademarks
OriginalFilename: 2ryoToyK.exe
ProductName: mteHpYSWUj
ProductVersion: 945
Translation: 0x0407 0x04b0

Generic.Dacic.635FDBB5.A.2E7C3A9C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanGeneric.Dacic.635FDBB5.A.2E7C3A9C
FireEyeGeneric.mg.79d3f3bc314f23d2
SkyhighGenericRXWF-QY!79D3F3BC314F
McAfeeGenericRXWF-QY!79D3F3BC314F
MalwarebytesSpyware.RedLineStealer
ZillyaTrojan.Stealer.Win32.131222
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win32/RedLineStealer.1e72704f
K7GWRiskware ( 00584baa1 )
K7AntiVirusTrojan ( 005a99e81 )
VirITTrojan.Win32.Genus.RSW
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUJS
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBC24
Paloaltogeneric.ml
ClamAVWin.Packed.Zpack-10005470-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGeneric.Dacic.635FDBB5.A.2E7C3A9C
NANO-AntivirusTrojan.Win32.Stealer.jxdpzv
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Kryptik.16000702
EmsisoftGeneric.Dacic.635FDBB5.A.2E7C3A9C (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
DrWebTrojan.PWS.RedLineNET.7
VIPREGeneric.Dacic.635FDBB5.A.2E7C3A9C
TrendMicroTROJ_GEN.R002C0DBC24
Trapminemalicious.high.ml.score
SophosTroj/Krypt-AAD
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminTrojanDownloader.Deyma.aqw
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen4
VaristW32/Kryptik.KCQ.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik.htvt
KingsoftWin32.Trojan-Spy.Stealer.gen
MicrosoftTrojan:Win32/RedLineStealer.L!MTB
XcitiumMalware@#1jf37qzop4y7b
ArcabitGeneric.Dacic.635FDBB5.A.2E7C3A9C
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.FNGDKA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R589377
BitDefenderThetaGen:NN.ZexaF.36804.Gq2@aGOaAGmi
ALYacGeneric.Dacic.635FDBB5.A.2E7C3A9C
VBA32Trojan.Kryptik
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.E841 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/Kryptik.HTVT!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudMalware

How to remove Generic.Dacic.635FDBB5.A.2E7C3A9C?

Generic.Dacic.635FDBB5.A.2E7C3A9C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment