Malware

Generic.Dacic.BE0F5EEA.A.8037436B (file analysis)

Malware Removal

The Generic.Dacic.BE0F5EEA.A.8037436B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.BE0F5EEA.A.8037436B virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Generic.Dacic.BE0F5EEA.A.8037436B?


File Info:

name: 1F64EF3C037BEE488319.mlw
path: /opt/CAPEv2/storage/binaries/635404f6c1af44cd301f2046c734e22ba96698d40667a3e67836618deb46c910
crc32: 332EF9F2
md5: 1f64ef3c037bee488319b9c2ecb3c30a
sha1: 7ac034f1f17e33200090c8a14d24c925ea01ff08
sha256: 635404f6c1af44cd301f2046c734e22ba96698d40667a3e67836618deb46c910
sha512: c581b620d6244dce671fd63a004adc518199f4dcdfc0645ecd33cf9061fcdec58d524d75abbccb281d0f25b8d6ae37827d9366d99a7790d033bae21b332fa7b9
ssdeep: 6144:z3Be8ySm8hQAAIfFrRXuEE+0l97mKwKSPwHVtVm86JQPDHDdx/Qtqa:E/zkFF+EExZmKbSPQVtoPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167A6CF3AB7C0CCF1C452C03236AA5E536DF56C301160AA67DB64DE492EF56E49B2A34F
sha3_384: 6f0e23047c94fb7f4678e00fa346f8887a74b334a405fb94b3fac28e47d21e4667be5dccaeb2c2349b34e6af5646837b
ep_bytes: 6a6068f0b74200e8edf7ffffbf940000
timestamp: 2006-12-09 08:21:07

Version Info:

0: [No Data]

Generic.Dacic.BE0F5EEA.A.8037436B also known as:

BkavW32.FxcaxMMUqhATTc.Worm
Elasticmalicious (high confidence)
DrWebTrojan.Siggen.36621
MicroWorld-eScanGeneric.Dacic.BE0F5EEA.A.8037436B
FireEyeGeneric.mg.1f64ef3c037bee48
CAT-QuickHealWorm.Pykspa.C3
McAfeeW32/Pykse.worm.gen.a
MalwarebytesGeneric.Worm.Agent.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.c037be
BitDefenderThetaGen:NN.ZexaF.34754.@pW@aOfj2pk
VirITTrojan.Win32.Generic.SXQ
CyrenW32/Pykspa.A.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.Agent.TG
APEXMalicious
TrendMicro-HouseCallWORM_AUTORUN_EK040404.UVPM
ClamAVWin.Worm.Pykspa-1
KasperskyTrojan-Ransom.Win32.Blocker.jcen
BitDefenderGeneric.Dacic.BE0F5EEA.A.8037436B
NANO-AntivirusTrojan.Win32.Agent.ctkmgw
AvastWin32:Renos-KY [Trj]
TencentWorm.Win32.Pykspa.a
Ad-AwareGeneric.Dacic.BE0F5EEA.A.8037436B
SophosML/PE-A + W32/Pykse-F
ComodoWorm.Win32.Autorun.Agent_TG0@1isiwy
BaiduWin32.Worm.Autorun.o
VIPREGeneric.Dacic.BE0F5EEA.A.8037436B
TrendMicroWORM_AUTORUN_EK040404.UVPM
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.BE0F5EEA.A.8037436B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.lhz
WebrootW32.Trojan.Vilsel.Gen
GoogleDetected
AviraTR/Agent.327680.A
Antiy-AVLTrojan/Generic.ASMalwS.7
ArcabitGeneric.Dacic.BE0F5EEA.A.8037436B
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmTrojan-Ransom.Win32.Blocker.jcen
GDataWin32.Trojan.BSE.1JWSKP9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
VBA32Trojan.ChidikSun.28205
ALYacGeneric.Dacic.BE0F5EEA.A.8037436B
MAXmalware (ai score=84)
RisingWorm.Autorun!1.BC87 (CLASSIC)
YandexTrojan.GenAsa!R41E4MI3PTc
TACHYONRansom/W32.Blocker.9904128.I
MaxSecureTrojan.Ransom.Blocker.iprw
FortinetW32/Agent.XEK!tr
AVGWin32:Renos-KY [Trj]
PandaTrj/Vilsel.B

How to remove Generic.Dacic.BE0F5EEA.A.8037436B?

Generic.Dacic.BE0F5EEA.A.8037436B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment