Trojan

Trojan-Notifier.Win32.AutoIt.a information

Malware Removal

The Trojan-Notifier.Win32.AutoIt.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Notifier.Win32.AutoIt.a virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Persian (Iran)
  • Unconventionial language used in binary resources: Farsi
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan-Notifier.Win32.AutoIt.a?


File Info:

name: 73DA35DA64DDBE9A7498.mlw
path: /opt/CAPEv2/storage/binaries/a7643384f48446fdf343641815b56ffd0106caab6ca6f08ae1caa2de39c7fa07
crc32: 8D190C76
md5: 73da35da64ddbe9a74984d4638fdc045
sha1: 4a62d2cc59cbbcc4f67f6d553587eed2a197793f
sha256: a7643384f48446fdf343641815b56ffd0106caab6ca6f08ae1caa2de39c7fa07
sha512: 4ca102d2e7ca15b93a45920ab65d5576ce8e2b0e77c118e7a9fb46e30d03a31d9d907a839d998ee1f45e18cdaa6aa2d12d47e760163745879b5d03953f2b4334
ssdeep: 24576:IAHnh+eWsN3skA4RV1Hom2KXMmHaSVRDSxBHP5:Ph+ZkldoPK8YaqoB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC3548036391803EEE96AF325A15A20156F8FD5555F3C52E33F83B69EB700F1126DE2A
sha3_384: 82dcc71c663f2fdc401fc6dc17644e54395556d5d5dadae4e0859363792504a929cdb9a788851b5b5de9dda67c7dcd3c
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-06-22 17:38:11

Version Info:

FileVersion: 10.4.10.2
Comments: http://www.autoitscript.com/autoit3/
FileDescription: Place to be home.
ProductVersion: 10.4.10.2
CompanyName: Place to be home.
LegalCopyright: Place to be home.
LegalTradeMarks: Place to be home.
Translation: 0x0429 0x04b0

Trojan-Notifier.Win32.AutoIt.a also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.AutoIt.g!c
MicroWorld-eScanTrojan.GenericKD.46530178
FireEyeTrojan.GenericKD.46530178
ALYacTrojan.GenericKD.46530178
CylanceUnsafe
K7AntiVirusTrojan ( 0057e8701 )
AlibabaTrojan:Win32/ClipBanker.cd885184
K7GWTrojan ( 0057e8701 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.FHLA-7850
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/ClipBanker.NL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Notifier.Win32.AutoIt.a
BitDefenderTrojan.GenericKD.46530178
NANO-AntivirusTrojan.Win32.AutoIt.jqcmuh
AvastWin32:Trojan-gen
TencentWin32.Trojan.Autoit.Jflw
Ad-AwareTrojan.GenericKD.46530178
SophosGeneric PUA EK (PUA)
ComodoMalware@#1e8w1qzyoltdn
VIPRETrojan.GenericKD.46530178
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftTrojan.GenericKD.46530178 (B)
GDataTrojan.GenericKD.46530178
WebrootW32.Trojan.Gen
AviraTR/ClipBanker.apilr
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2C5FE82
MicrosoftTrojan:Win32/CryptInject!MSR
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4535597
McAfeeArtemis!73DA35DA64DD
MAXmalware (ai score=80)
VBA32TrojanNotifier.AutoIt
IkarusTrojan.Win32.Clipbanker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan-Notifier.Win32.AutoIt.a?

Trojan-Notifier.Win32.AutoIt.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment