Trojan

What is “AIT:Trojan.GenericTKA.353”?

Malware Removal

The AIT:Trojan.GenericTKA.353 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.GenericTKA.353 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine AIT:Trojan.GenericTKA.353?


File Info:

name: B89BFBE199C666C8F38C.mlw
path: /opt/CAPEv2/storage/binaries/f9d84111aae2c57ea9c1dddbf5a531020ac0728ba902d73e57bcfa4fa757fd6f
crc32: EC20A6DC
md5: b89bfbe199c666c8f38c29bee63ee5eb
sha1: 0a41031976ee8cd0cceb40b49382aaed5a442187
sha256: f9d84111aae2c57ea9c1dddbf5a531020ac0728ba902d73e57bcfa4fa757fd6f
sha512: 24ba696d3f72ddaacd10112ac8b4de6233d26ac43d8f8b0a8b67f7a305e6fa0589ed16b86c19eb0eb46e0de5b33b3946c5e99f96a02dedb251c944442f9be229
ssdeep: 24576:8PatCg7EPimZbPv63cCEpshK9pmE0Q3Fpm51TmrMpuUFQIr+:vtV7EPimI3c8zA1YjuUKQ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16725238BA19A252FFD542231C523EBAF66B2FBC1C27135AA50E8683F1D3D392CC91554
sha3_384: df43d990d53cf62529bd1da73ad1ff2bae972fd180f4c0e85ab948ab2fe38f400c33df496034b57cd7582ca4e77b874c
ep_bytes: 60be002046008dbe00f0f9ff57eb0b90
timestamp: 2008-06-12 08:51:05

Version Info:

FileDescription:
FileVersion: 3, 2, 12, 1
CompiledScript: AutoIt v3 Script : 3, 2, 12, 1
Translation: 0x0809 0x04b0

AIT:Trojan.GenericTKA.353 also known as:

LionicTrojan.Win32.Genome.linK
CynetMalicious (score: 99)
FireEyeAIT:Trojan.GenericTKA.353
McAfeeArtemis!B89BFBE199C6
VIPREAIT:Trojan.GenericTKA.353
AlibabaTrojan:Win32/Generic.21d0e6bb
Cybereasonmalicious.199c66
BitDefenderThetaAI:Packer.1581F47719
Elasticmalicious (moderate confidence)
APEXMalicious
KasperskyTrojan.Win32.Autoit.afx
BitDefenderAIT:Trojan.GenericTKA.353
NANO-AntivirusTrojan.Script.Autoit.debvkh
MicroWorld-eScanAIT:Trojan.GenericTKA.353
AvastWin32:Malware-gen
Ad-AwareAIT:Trojan.GenericTKA.353
SophosGeneric ML PUA (PUA)
ComodoMalware@#lsxpaj2h82gw
F-SecureHeuristic.HEUR/AGEN.1201044
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
EmsisoftAIT:Trojan.GenericTKA.353 (B)
IkarusTrojan.AutoIt.GenericTKA
GDataAIT:Trojan.GenericTKA.353 (3x)
AviraHEUR/AGEN.1201044
ArcabitAIT:Trojan.GenericTKA.353
ZoneAlarmTrojan.Win32.Autoit.afx
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacAIT:Trojan.GenericTKA.353
MAXmalware (ai score=82)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R067H0CHF22
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove AIT:Trojan.GenericTKA.353?

AIT:Trojan.GenericTKA.353 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment