Malware

Should I remove “Generic.Dacic.9E6FF5C2.A.54A3A609”?

Malware Removal

The Generic.Dacic.9E6FF5C2.A.54A3A609 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.9E6FF5C2.A.54A3A609 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.9E6FF5C2.A.54A3A609?


File Info:

name: 2762B8A3FC196068899C.mlw
path: /opt/CAPEv2/storage/binaries/430e4a553b092673b7c9a4784a032e5d261fa43bd6bcfc3cec11115a147f47b7
crc32: 356DCFC6
md5: 2762b8a3fc196068899c2ff026a778dc
sha1: d2333cfdd71a9010147fdcdca788a3c69e486f23
sha256: 430e4a553b092673b7c9a4784a032e5d261fa43bd6bcfc3cec11115a147f47b7
sha512: 056ebc125574d45669469bad1ae909649e3aa4ca77b4845f3eec22daeb19e48e2e3e6e5677d6800662adc5874e45790a7b8ad8e734b54b34b8993592244a2089
ssdeep: 6144:Qy/stEHoXUY+pUum3UAa5O24kCzaSSxWhguas9NTX/mgFsd:QGDgUY+wUz5O24kCzzhguas9NTOg2d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAB4E913B6229491E1145BF66BBA073869F8872038B1CE23EFE4DD71BD75532874E60E
sha3_384: f9578c20f7c7936cc835ca2a4101922913ca144e56b79a6c03fdd291d146569ea4d2deebf2b1d23dc70839acebd3daff
ep_bytes: e8cb9f0500e81885050033c0c3909090
timestamp: 2015-01-27 06:39:28

Version Info:

0: [No Data]

Generic.Dacic.9E6FF5C2.A.54A3A609 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.ts9h
tehtrisGeneric.Malware
MicroWorld-eScanDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.2762b8a3fc196068
CAT-QuickHealRisktool.Flystudio.17330
SkyhighBehavesLike.Win32.Generic.hm
McAfeePWS-FCCD!2762B8A3FC19
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Scar.Win32.142559
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusPassword-Stealer ( 004b38871 )
AlibabaMalware:Win32/km_241a4.None
K7GWPassword-Stealer ( 004b38871 )
Cybereasonmalicious.dd71a9
ArcabitDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609
BaiduWin32.Trojan-PSW.QQPass.p
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.QQPass.OUO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ihrb
BitDefenderDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609
NANO-AntivirusTrojan.Win32.Scar.dndoym
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Qqpass.16000300
EmsisoftDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609 (B)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.DownLoader12.29778
VIPREDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609
Trapminemalicious.high.ml.score
SophosTroj/Agent-BBAC
IkarusTrojan.Win32.Hider
JiangminTrojan/Scar.bdov
GoogleDetected
AviraADWARE/Adware.Gen
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftPWS:Win32/QQpass.A!MTB
ZoneAlarmTrojan.Win32.Scar.ihrb
GDataWin32.Trojan.PSE.18PVCNI
VaristW32/S-b7d25ce6!Eldorado
AhnLab-V3Trojan/Win32.Stealer.R143066
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.GqX@aysLICb
ALYacDeepScan:Generic.Dacic.9E6FF5C2.A.54A3A609
MAXmalware (ai score=88)
VBA32BScope.Trojan.StartPage
Cylanceunsafe
PandaTrj/Genetic.gen
RisingStealer.QQPass!1.9FF2 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Zusy.307491!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Dacic.9E6FF5C2.A.54A3A609?

Generic.Dacic.9E6FF5C2.A.54A3A609 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment