Backdoor

GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF removal instruction

Malware Removal

The GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF?


File Info:

name: D8491281BB411DAF1541.mlw
path: /opt/CAPEv2/storage/binaries/b464aaa0fccfd40d3fc3ce49c06889d0eb1575ad5166bfc390e8bc6c719566ad
crc32: 8422C42D
md5: d8491281bb411daf1541b18c9e0d69e4
sha1: 42ec68041bf071bfafb07ecc034dc7903eb695b8
sha256: b464aaa0fccfd40d3fc3ce49c06889d0eb1575ad5166bfc390e8bc6c719566ad
sha512: ff68cc258298f981b3f679e7437fe7dfd6aad048eb559a5d126b52b2c23315d129f85a0a7b7640cff5c8d0510c4f9eebf99239db83b0341c906ac14a05cd5ae5
ssdeep: 6144:MvxetIyedZwlNPjLs+H8rtMsQBJyJyymeH:YxzyGZwlNPjLYRMsXJvmeH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6745A79F7A80771C7862232261B1896DB38CCAC1F6570D35778D31A1A36CE0C5B6BB6
sha3_384: b881986cc47bb56cb2b28f8f21a5b083db4e0e048b52b260ac387c9d86a98476f383d4af3e4c984ff8bea82913e0ec24
ep_bytes: 60909090909067e80000000090909090
timestamp: 2018-07-09 22:06:51

Version Info:

0: [No Data]

GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43791
MicroWorld-eScanGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF
ClamAVWin.Trojan.Crypted-36
FireEyeGeneric.mg.d8491281bb411daf
CAT-QuickHealBackdoor.Berbew.A6.MUE
McAfeeGenericRXVP-YB!D8491281BB41
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.8B6893E621
VirITWorm.Win32.Berbew.G
CyrenW32/Padodor.F.gen!Eldorado
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
BaiduWin32.Trojan-Spy.Quart.a
ZillyaTrojan.Qukart.Win32.1042082
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fh
Trapminemalicious.high.ml.score
SophosTroj/Padodo-Fam
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojanProxy.Qukart.bqyi
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
VBA32BScope.Backdoor.Berbew
ALYacGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.PR.Qukart!MRIP3jtd7Kk
IkarusTrojan-Spy.Win32.Qukart
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF?

GenPack:Generic.Dacic.1.Backdoor.Hangup.A.0E1725CF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment