Malware

Generic.Dacic.D6DFC400.A.C3C69D00 removal instruction

Malware Removal

The Generic.Dacic.D6DFC400.A.C3C69D00 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.D6DFC400.A.C3C69D00 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the NjRATGolden malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.D6DFC400.A.C3C69D00?


File Info:

name: CA3778BD7773C58A1C51.mlw
path: /opt/CAPEv2/storage/binaries/d51557e0c5f23147324c26aba2b02cdc29b48fc60de3bdfd982584f8b2d86aca
crc32: 7460FCB9
md5: ca3778bd7773c58a1c5159b99d02e929
sha1: 5c5334697873a884f782ee6b2c0251e5ee1e8de1
sha256: d51557e0c5f23147324c26aba2b02cdc29b48fc60de3bdfd982584f8b2d86aca
sha512: 5303900aa161164e9a19ac2f0386109b69c95f7fdd217f1b5e377eec95acfeeea287b148a0383746fc905a9916423af3ad5f2608d5169d03755854a099f1e42b
ssdeep: 768:V0So+WoOpKD9Rxn0qiU+4hs+o3Ehq5lxOBcmZPtUsjC:V0So+s4Lxn0qiU1hlW5lxOWmsZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122F2FA8DBFE24194C2FD5E734671D2220376E00B1A23D76D8EF844B65AA36848F5CED6
sha3_384: f06c7b558b91412e03d92414a0a176bcb72ea381f18099309c30f6f0b008cfc3cab78142ea546999234f298ae5656bb6
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-05 14:19:57

Version Info:

0: [No Data]

Generic.Dacic.D6DFC400.A.C3C69D00 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebBackDoor.BladabindiNET.8
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S19436243
McAfeeTrojan-FIGN
Cylanceunsafe
ZillyaWorm.Bladabindi.Win32.16638
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:MSIL/njRAT.7e993c1a
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d7773c
BitDefenderThetaGen:NN.ZemsilF.36348.cmW@aCgHW1b
VirITTrojan.Win32.MSIL.IM
CyrenW32/MSIL_Troj.AP.gen!Eldorado
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
ClamAVWin.Trojan.B-468
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.D6DFC400.A.C3C69D00
NANO-AntivirusTrojan.Win32.Bladabindi.jxewis
ViRobotTrojan.Win.Z.Dacic.36864
MicroWorld-eScanGeneric.Dacic.D6DFC400.A.C3C69D00
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Win32.Bladabindi.16000442
EmsisoftWorm.Bladabindi (A)
F-SecureTrojan.TR/ATRAPS.Gen
BaiduMSIL.Backdoor.Bladabindi.a
VIPREGeneric.Dacic.D6DFC400.A.C3C69D00
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ca3778bd7773c58a
SophosTroj/Bbindi-W
IkarusTrojan.Crypter
GDataMSIL.Trojan.PSE.13IYHXI
JiangminTrojanDropper.Autoit.dce
AviraTR/ATRAPS.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/MSIL.Bladabindi
XcitiumTrojWare.MSIL.Spy.Agent.CP@4pqytu
ArcabitGeneric.Dacic.D6DFC400.A.C3C69D00
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/njRAT.RDSA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R419483
Acronissuspicious
VBA32Trojan.MSIL.Bladabindi.Heur
ALYacGeneric.Dacic.D6DFC400.A.C3C69D00
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Dacic.D6DFC400.A.C3C69D00?

Generic.Dacic.D6DFC400.A.C3C69D00 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment