Malware

Generic.Dacic.DED21A61.A.49D70D53 (file analysis)

Malware Removal

The Generic.Dacic.DED21A61.A.49D70D53 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.DED21A61.A.49D70D53 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.DED21A61.A.49D70D53?


File Info:

name: D14FB79629106F1FF119.mlw
path: /opt/CAPEv2/storage/binaries/9c1e948baa76435b06ad204abdab24083913a69ee40e539455eacdebf3145cb0
crc32: E897FA64
md5: d14fb79629106f1ff119ed890259d969
sha1: d8fd82699df57d6f52f967f14492352ad22b6839
sha256: 9c1e948baa76435b06ad204abdab24083913a69ee40e539455eacdebf3145cb0
sha512: d7723175378809f2b168a618fdfa80e077ef8507f41e758c3901a7d73f825b9ca0377fb42bec352b83b81c875458ed62d41596ce529bef8d0f358a8c8ec010d5
ssdeep: 1536:d+L8V2eJkJG6bFSZHALyaqrd4Xwohhhh8:d3+JG6ZSZHDaqZ4Xwohhhh8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA334AC5EBA1889DD26887F016764AB39427EC497B124E9BC7C0FD3D58374CE8D1628E
sha3_384: 96bcd9c21c44fb59f6a539df35d29ab3ee90aa81da1261f15c553231e9d813819e8f8de95c8a50bd1820272b9f0af276
ep_bytes: 558bec6aff68c845400068ae30400064
timestamp: 2017-05-28 15:44:20

Version Info:

Comments: OMFG Studio
CompanyName: OMFG Studio
FileDescription: Clien Local RunPross Auto
FileVersion: 32, 2,34, 5374
InternalName: Clock
LegalCopyright: OMFG Studio All rights reserved.
LegalTrademarks:
OriginalFilename: Clock.exe
PrivateBuild:
ProductName: Clock.exe
ProductVersion: 32, 2,34, 5374
SpecialBuild:
Translation: 0x0804 0x04b0

Generic.Dacic.DED21A61.A.49D70D53 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.63361
MicroWorld-eScanDeepScan:Generic.Dacic.DED21A61.A.49D70D53
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Magania.Win32.75132
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 00560bb71 )
Cybereasonmalicious.99df57
BitDefenderThetaGen:NN.ZexaF.36662.dq1@aSESn3hj
CyrenW32/ServStart.Z.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ServStart.OP
APEXMalicious
ClamAVWin.Malware.Bavs-6804154-0
KasperskyTrojan-GameThief.Win32.Magania.uhbd
BitDefenderDeepScan:Generic.Dacic.DED21A61.A.49D70D53
NANO-AntivirusTrojan.Win32.Magania.epgxys
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bf1753
EmsisoftDeepScan:Generic.Dacic.DED21A61.A.49D70D53 (B)
F-SecureTrojan.TR/ServStart.bwojd
VIPREDeepScan:Generic.Dacic.DED21A61.A.49D70D53
McAfee-GW-EditionBehavesLike.Win32.Generic.pm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d14fb79629106f1f
SophosTroj/Agent-BCHT
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10FZMY3
JiangminTrojan.Generic.azxao
GoogleDetected
AviraTR/ServStart.bwojd
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.ServStart.CB@7486ss
ArcabitDeepScan:Generic.Dacic.DED21A61.A.49D70D53
ZoneAlarmTrojan-GameThief.Win32.Magania.uhbd
MicrosoftDDoS:Win32/Nitol!atmnm
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Magania.C5473132
VBA32BScope.Trojan.Downloader
ALYacDeepScan:Generic.Dacic.DED21A61.A.49D70D53
Cylanceunsafe
PandaTrj/GdSda.A
ZonerTrojan.Win32.88636
RisingDownloader.Unruy!8.D8 (TFE:5:FGdIfFpxOuK)
YandexTrojan.GenAsa!tTgzBkWN6RQ
IkarusBackdoor.Win32.Inject
FortinetW32/GenKryptik.AWIY!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Dacic.DED21A61.A.49D70D53?

Generic.Dacic.DED21A61.A.49D70D53 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment