Malware

Should I remove “Generic.Dacic.Emdup.A.962AE9DB”?

Malware Removal

The Generic.Dacic.Emdup.A.962AE9DB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.Emdup.A.962AE9DB virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generic.Dacic.Emdup.A.962AE9DB?


File Info:

name: DB503366284E8BD2550B.mlw
path: /opt/CAPEv2/storage/binaries/a5712821bf6bd1f3ede6163d8ae3253ab33d0a73afa46b431898c0db70c21f41
crc32: 9F5B85E8
md5: db503366284e8bd2550b0e162bc676d9
sha1: f9e4e94ec1350a220681a6e3602e1444287d7554
sha256: a5712821bf6bd1f3ede6163d8ae3253ab33d0a73afa46b431898c0db70c21f41
sha512: 3079fba9b6a2b08db3363c2cfff8b4a3ec3296b072c230f57702ec26406d9b8edf98b2578f7d2ce405ace11fe9afda414e43b2840b87d81465e362a7cc263da3
ssdeep: 3072:L4oBsQ3tGXRvjxCb5NgXDY7uSlkJcUa7kYQTcqW2NdQQGH/UDhSCUc4aqTBW8wJu:5olKgzelZNQSBQGH/CSpWqT48Nk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C54D0C13992C6F1E2E14DFE44B6AE518736AD035A20C593B39D3A6F1EB32DC1A97107
sha3_384: 6d568442cc2bfb6ab3a50bde5be5c8c16663fe4d31a17c0536a3859923e2874a322779721fdf44912ac4ae8e4cf76c7a
ep_bytes: e812470000e916feffff55545d81ec28
timestamp: 2008-09-27 04:51:42

Version Info:

FileDescription: AutoHotkey Unicode 64-bit
FileVersion: 1.1.36.02
InternalName: AutoHotkey
LegalCopyright: Copyright (C) 2003-2013
CompanyName: AutoHotkey Foundation LLC
OriginalFilename: AutoHotkey.exe
ProductName: AutoHotkey
ProductVersion: 1.1.36.02
Translation: 0x0409 0x04b0

Generic.Dacic.Emdup.A.962AE9DB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.Emdup.A.962AE9DB
CAT-QuickHealTrojan.CosmuRI.S10808321
SkyhighBehavesLike.Win32.Generic.dh
McAfeeGeneric-FAEY!DB503366284E
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Agent.Win32.57943
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00463de51 )
BitDefenderGeneric.Dacic.Emdup.A.962AE9DB
K7GWTrojan ( 00463de51 )
Cybereasonmalicious.ec1350
BitDefenderThetaGen:NN.ZexaF.36792.rq3@aKaDHkn
VirITTrojan.Win32.Generic.BERI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NLP
APEXMalicious
ClamAVWin.Worm.Generic-9786786-0
KasperskyHEUR:Trojan.Win32.Cosmu.gen
NANO-AntivirusTrojan.Win32.Mlw.hzygwo
RisingWorm.Agent!1.DAFA (CLASSIC)
SophosW32/Renamer-V
BaiduWin32.Worm.Agent.bg
F-SecureWorm.WORM/Agent.2170901
DrWebWin32.HLLW.Siggen.10550
VIPREGeneric.Dacic.Emdup.A.962AE9DB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.db503366284e8bd2
EmsisoftGeneric.Dacic.Emdup.A.962AE9DB (B)
IkarusWorm.Agent
MAXmalware (ai score=85)
JiangminWorm.Generic.aohc
Webroot
GoogleDetected
AviraWORM/Agent.2170901
VaristW32/Agent.QP.gen!Eldorado
Antiy-AVLGrayWare/Win32.Agent.nlp
Kingsoftmalware.kb.a.997
MicrosoftVirus:Win32/Emdup.A
XcitiumWorm.Win32.Agent.NLPA@4t56ql
ArcabitGeneric.Dacic.Emdup.A.962AE9DB
ZoneAlarmHEUR:Trojan.Win32.Cosmu.gen
GDataWin32.Trojan.PSE.16P8D2E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ADH.R47876
Acronissuspicious
VBA32BScope.Trojan.Sabsik.FL
ALYacGeneric.Dacic.Emdup.A.962AE9DB
TACHYONWorm/W32.Cosmu.B
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.82524
TencentTrojan.Win32.Cosmu.c
YandexTrojan.GenAsa!LdHJgsFIunw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NLP!worm
AVGWin32:WormX-gen [Wrm]
AvastWin32:WormX-gen [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Dacic.Emdup.A.962AE9DB?

Generic.Dacic.Emdup.A.962AE9DB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment