Malware

AdWare.Win32.Acon.bad removal tips

Malware Removal

The AdWare.Win32.Acon.bad is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Acon.bad virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings

Related domains:

aurevoir.club

How to determine AdWare.Win32.Acon.bad?


File Info:

name: B8BEE89DC823D6A7D6FD.mlw
path: /opt/CAPEv2/storage/binaries/d9c4747a0ee1676b0e127cade4be51f30c740d67c3b6302a74468ba41fee207b
crc32: 6C419142
md5: b8bee89dc823d6a7d6fdfc1479376d37
sha1: a942b42b7d340a0e56d89c5038533bf119753b7e
sha256: d9c4747a0ee1676b0e127cade4be51f30c740d67c3b6302a74468ba41fee207b
sha512: f0ee26f94e2802f45c3f252ef6bee10223157a16edd9b4b2834d128ede83a5360940b8234783613afd37e35f4c0a0ef51e4dcf0023a31c5f62246d80bd568329
ssdeep: 768:81cVhpQI2EQK0iPDh84nScF15GYbWjXO3XJd5DUvcy6tXcoi2z3/n:aQpQ5EP0ijnRTXJd5DUvcblcQzP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A33C01636C5C4BBD4634B311AB7EB27E3BAF704162107576B602FBF3A12183C61A296
sha3_384: 42cfe5bcd61f295ff80047aa157cea5678401c2c9328f9551284f82ecba76ad997ba04a2d72b714ad5bcfc5111e95462
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

CompanyName: AOeumXGdgQJ099SdCGk
Translation: 0x0000 0x04e4

AdWare.Win32.Acon.bad also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Acon.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.3444276
FireEyeTrojan.GenericKD.3444276
CAT-QuickHealSftwrBndlr.NSIS.Fourthrem.A
ALYacTrojan.GenericKD.3444276
MalwarebytesTrojan.Script
AlibabaTrojanDownloader:Win32/CoinMiner.fbcc354a
Cybereasonmalicious.dc823d
SymantecDownloader
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Acon.bad
BitDefenderTrojan.GenericKD.3444276
NANO-AntivirusRiskware.Win32.Ocna.ehzayx
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastFileRepMalware [PUP]
TencentWin32.Adware.Ocna.Phqk
Ad-AwareTrojan.GenericKD.3444276
SophosGeneric PUA KJ (PUA)
DrWebTrojan.DownLoader22.12006
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.pc
EmsisoftTrojan.GenericKD.3444276 (B)
SentinelOneStatic AI – Malicious PE
GDataNSIS.Application.Fourthrem.A
AviraHEUR/AGEN.1127440
Antiy-AVLTrojan/Generic.ASMalwNS.3E1
KingsoftWin32.Troj.Ocna.b.(kcloud)
ArcabitTrojan.Generic.D348E34
MicrosoftTrojan:Win32/Tilken.B!cl
CynetMalicious (score: 99)
McAfeeArtemis!B8BEE89DC823
VBA32suspected of Trojan.Downloader.gen
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0WGR21
FortinetAdware/Ocna
WebrootTrojan.Dropper.Gen
AVGFileRepMalware [PUP]
PandaTrj/CI.A

How to remove AdWare.Win32.Acon.bad?

AdWare.Win32.Acon.bad removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment