Categories: Malware

AIT.Acapulco.8.Gen removal instruction

The AIT.Acapulco.8.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT.Acapulco.8.Gen virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine AIT.Acapulco.8.Gen?


File Info:

crc32: 8DE63674md5: 341d91cbc02b0108b52c17c218b68c4cname: winlog.exesha1: 1b4a080701b757f420b523921fd59f52d7960d9dsha256: cd1b06f7fd3f246722daff9140a2c35035522797479600479a0bd91d641482a1sha512: 1e463f4d44b15600a8aab81612f787a116ab3046a691b4d8a8bd05bcd46d5833783c9f201b2ec1344631e5adbc5c32c5b8bf9b313025568d88b018f2a0b85bc9ssdeep: 24576:jtb20pkaCqT5TBWgNQ7aj3KBg3zmCGCGxK40O5Dos+5rJwWvIgWPWNI0tLUlUdP:gVg5tQ7ajCJ50EoxrKWwtWNI0tMc5type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

AIT.Acapulco.8.Gen also known as:

MicroWorld-eScan AIT.Acapulco.8.Gen
FireEye Generic.mg.341d91cbc02b0108
McAfee Artemis!341D91CBC02B
Cylance Unsafe
AegisLab Trojan.Script.Generic.4!c
BitDefender AIT.Acapulco.8.Gen
K7GW Trojan ( 005671bd1 )
Cybereason malicious.701b75
Invincea heuristic
Symantec Trojan.Gen.MBT
APEX Malicious
Avast Script:SNH-gen [Trj]
GData AIT.Acapulco.8.Gen
Kaspersky HEUR:Trojan.Script.Generic
Alibaba Trojan:Win32/Injector.2712b191
Endgame malicious (high confidence)
F-Secure Trojan.TR/AD.Swotter.hys
DrWeb Trojan.Siggen9.47967
Emsisoft AIT.Acapulco.8.Gen (B)
Ikarus Win32.Outbreak
Cyren W32/AutoIt.OM.gen!Eldorado
Avira TR/AD.Swotter.hys
MAX malware (ai score=87)
Antiy-AVL GrayWare/Autoit.BinToStr.a
Microsoft Trojan:Win32/Predator.ARA!MTB
Arcabit AIT.Acapulco.8.Gen
ZoneAlarm HEUR:Trojan.Script.Generic
Malwarebytes Trojan.MalPack.AutoIt.Generic
Panda Trj/CI.A
ESET-NOD32 a variant of Win32/Injector.Autoit.FHY
TrendMicro-HouseCall TROJ_GEN.R002H01EL20
Rising Trojan.Obfus/Autoit!1.C6C8 (CLASSIC)
MaxSecure Trojan.Malware.300983.susgen
Fortinet AutoIt/Injector.FHI!tr
Ad-Aware AIT.Acapulco.8.Gen
AVG Script:SNH-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Generic/Trojan.Script.ed4

How to remove AIT.Acapulco.8.Gen?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

W32/SillyFDC-GT removal guide

The W32/SillyFDC-GT is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Generic.Dacic.1206.5BCB2804 removal instruction

The Generic.Dacic.1206.5BCB2804 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

MSIL/Kryptik.OM removal instruction

The MSIL/Kryptik.OM is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Trojan:MSIL/PureLogs.SK!MTB removal

The Trojan:MSIL/PureLogs.SK!MTB is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Trojan:MSIL/AgentTesla.PSXP!MTB removal instruction

The Trojan:MSIL/AgentTesla.PSXP!MTB is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

About “IL:Trojan.MSILZilla.33267” infection

The IL:Trojan.MSILZilla.33267 is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago