Malware

Generic.Dacic.DF00ABC1.A.EDDC60DA (file analysis)

Malware Removal

The Generic.Dacic.DF00ABC1.A.EDDC60DA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.DF00ABC1.A.EDDC60DA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.DF00ABC1.A.EDDC60DA?


File Info:

name: 68FE9FF2210E5EE77DD5.mlw
path: /opt/CAPEv2/storage/binaries/dc7ba08971bf24a8dbcffff618a4873b5a26200aa2155f691e702bef3f07d3e8
crc32: 99D26B3D
md5: 68fe9ff2210e5ee77dd5601c7a81d7cc
sha1: d7b6e1e13aff44fc64bd08c3f59ea685a9a5308c
sha256: dc7ba08971bf24a8dbcffff618a4873b5a26200aa2155f691e702bef3f07d3e8
sha512: 7fe7f591e9dc7e460433ea955527d2133f650d52085f3e47f1a7db53526453ecb2a449151e468f8afa34a15b1d7af096185b862a127bab7f2582e0c3b0e20839
ssdeep: 6144:/FZmB0OqFNLVJ6S0lE+6LVjlWPuEwTIwMe/wwULcj:/zlhNLVJ/nLVjlWPuEw6c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11344C72B62D0F33AE121CAF5695983B4452EBC3115C6A807F7C12F1A77B1DA7A231727
sha3_384: f9ed25a0722afbd62e86632c3ba181b2204429af29866ac48e954fed9456d4ff844d56e565e9b80ec25bc590a82d3fbc
ep_bytes: 68ac4a4000e8eeffffff000000000000
timestamp: 2012-10-13 18:27:31

Version Info:

Translation: 0x0409 0x04b0
ProductName: Croupiness
FileVersion: 6.53
ProductVersion: 6.53
InternalName: Silvanus
OriginalFilename: Silvanus.exe

Generic.Dacic.DF00ABC1.A.EDDC60DA also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.mepT
MicroWorld-eScanGeneric.Dacic.DF00ABC1.A.EDDC60DA
ClamAVWin.Packer.VBCrypt-5731517-0
FireEyeGeneric.mg.68fe9ff2210e5ee7
CAT-QuickHealTrojan.Beebone.D
ALYacGeneric.Dacic.DF00ABC1.A.EDDC60DA
MalwarebytesVBObfus.Worm.Spreader.DDS
ZillyaTrojan.Jorik.Win32.1069403
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Jorik.f4907385
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.CKRZ
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBObfus.CZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.gdcp
BitDefenderGeneric.Dacic.DF00ABC1.A.EDDC60DA
BitDefenderThetaAI:Packer.F336BC9120
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AETI [Trj]
TencentTrojan.Win32.Jorik.co
TACHYONTrojan/W32.VB-Jorik.270336.E
EmsisoftGeneric.Dacic.DF00ABC1.A.EDDC60DA (B)
F-SecureTrojan.TR/Barys.2655987
DrWebTrojan.DownLoader7.7390
VIPREGeneric.Dacic.DF00ABC1.A.EDDC60DA
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
SophosMal/SillyFDC-W
IkarusTrojan.Win32.Otran
GDataGeneric.Dacic.DF00ABC1.A.EDDC60DA
JiangminWorm/Vobfus.ivb
AviraTR/Barys.2655987
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitGeneric.Dacic.DF00ABC1.A.EDDC60DA
ViRobotWorm.Win32.A.Vobfus.270336
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gdcp
MicrosoftWorm:Win32/Vobfus.gen!X
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R42639
McAfeeGenDownloader.rv
MAXmalware (ai score=100)
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingWorm.Win32.WBNA.r (CLASSIC)
YandexTrojan.GenAsa!e7X6q2T9WMM
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.9968741.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AETI [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Dacic.DF00ABC1.A.EDDC60DA?

Generic.Dacic.DF00ABC1.A.EDDC60DA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment