Malware

Generic.Dacic.D6DFC400.A.5FEDB975 removal guide

Malware Removal

The Generic.Dacic.D6DFC400.A.5FEDB975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.D6DFC400.A.5FEDB975 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the NjRATGolden malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.D6DFC400.A.5FEDB975?


File Info:

name: 021581BD649E439927BF.mlw
path: /opt/CAPEv2/storage/binaries/33c6176105897c08be46ad8a06ad7b8855ea58514c90d753463bcc4d75070bb6
crc32: 5AF83227
md5: 021581bd649e439927bf7c3433a0df5f
sha1: fde77e5490dcfb495aecec9770a3ea9b58436fc4
sha256: 33c6176105897c08be46ad8a06ad7b8855ea58514c90d753463bcc4d75070bb6
sha512: ebc81f5bc69c694c73167c63693a6806c811576a9e2f1deb5ea4e8ecb2a048e296ead9c5da05e876b4fc2f154977d290a5efc0b3462461fbf7b847bfb6592474
ssdeep: 384:PNj3siDpT95hL5YyUvvlPNVm4iGpT8rAF+rMRTyN/0L+EcoinblneHQM3epzXUN9:Fjpv5zUvvlW1GJ8rM+rMRa8NuWtt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107033B4D7FE1816CC5FD057B06B2D01207BAE04F6E23D91E8EE564AA37636C58B50AF2
sha3_384: 5c0bab3f37cee1d3cd869c0b9b4159db725de1538fc89129bb4c993afa715e45e194f36ca2cc0f5af9cd4d9e5be1d08b
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-24 17:21:41

Version Info:

0: [No Data]

Generic.Dacic.D6DFC400.A.5FEDB975 also known as:

MicroWorld-eScanGeneric.Dacic.D6DFC400.A.5FEDB975
FireEyeGeneric.mg.021581bd649e4399
CAT-QuickHealTrojan.GenericFC.S19436243
SkyhighBehavesLike.Win32.Generic.nm
ALYacGeneric.Dacic.D6DFC400.A.5FEDB975
MalwarebytesBladabindi.Backdoor.Bot.DDS
ZillyaTrojan.Bladabindi.Win32.73617
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.36792.cmW@aOg8nCd
VirITTrojan.Win32.DownLoader21.BPQW
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.D6DFC400.A.5FEDB975
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
TACHYONBackdoor/W32.DN-NjRat.37888.AF
EmsisoftWorm.Bladabindi (A)
BaiduMSIL.Backdoor.Bladabindi.a
F-SecureTrojan.TR/ATRAPS.Gen
DrWebBackDoor.BladabindiNET.8
VIPREGeneric.Dacic.D6DFC400.A.5FEDB975
TrendMicroBKDR_BLADABI.SMC
Trapminemalicious.high.ml.score
SophosTroj/Bbindi-W
IkarusTrojan.Inject
JiangminTrojanDropper.Autoit.dce
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
Kingsoftmalware.kb.c.1000
MicrosoftTrojan:MSIL/njRAT.RDSA!MTB
XcitiumTrojWare.MSIL.Spy.Agent.CP@4pqytu
ArcabitGeneric.Dacic.D6DFC400.A.5FEDB975
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan-Spy.Bladabindi.BQ
VaristW32/MSIL_Troj.AP.gen!Eldorado
AhnLab-V3Trojan/Win32.RL_Generic.C4264981
McAfeeTrojan-FIGN
MAXmalware (ai score=80)
VBA32Trojan.MSIL.Bladabindi.Heur
Cylanceunsafe
ZonerTrojan.Win32.84773
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
Cybereasonmalicious.490dcf
DeepInstinctMALICIOUS

How to remove Generic.Dacic.D6DFC400.A.5FEDB975?

Generic.Dacic.D6DFC400.A.5FEDB975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment