Malware

About “AIT.Heur.Acapulco.11.768BA367.Gen (B)” infection

Malware Removal

The AIT.Heur.Acapulco.11.768BA367.Gen (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT.Heur.Acapulco.11.768BA367.Gen (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.uguu.se
a.tomx.xyz

How to determine AIT.Heur.Acapulco.11.768BA367.Gen (B)?


File Info:

crc32: 1759FA34
md5: ad9354f45377d8cedc5ab0cc1e239390
name: AD9354F45377D8CEDC5AB0CC1E239390.mlw
sha1: 000758cd5397685aac17d568e95870e1bf043675
sha256: 1104b201580461c0319cf6fb65b219a56093ff425a8788758be9949242cea2e4
sha512: 05df375fcde80b4b436744509b1c56a6c7b761a0e17dd60671ca74a7efa7103704de7f15dbe1c7b79645e90cffee66fe6bf7911c07b30b6c6fde394ea6b61db4
ssdeep: 6144:44XrK9PX7Fp6Gh2wWRGl0EDDf1PisZQ5rAGQwg1QtP1f4paaYlsdcaMJEdbI0Pz:nXe9PPlowWX0t6mOQwg1Qd15CcYk0We
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

AIT.Heur.Acapulco.11.768BA367.Gen (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacAIT.Heur.Acapulco.11.768BA367.Gen
CylanceUnsafe
ZillyaTrojan.ProxyChanger.Win32.1933
SangforTrojan.Win32.Save.a
BitDefenderAIT.Heur.Acapulco.11.768BA367.Gen
Cybereasonmalicious.45377d
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanAIT.Heur.Acapulco.11.768BA367.Gen
Ad-AwareAIT.Heur.Acapulco.11.768BA367.Gen
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.ad9354f45377d8ce
EmsisoftAIT.Heur.Acapulco.11.768BA367.Gen (B)
WebrootW32.Trojan.GenKD
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAIT.Heur.Acapulco.11.768BA367.Gen (3x)
McAfeeArtemis!AD9354F45377
MAXmalware (ai score=86)

How to remove AIT.Heur.Acapulco.11.768BA367.Gen (B)?

AIT.Heur.Acapulco.11.768BA367.Gen (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment