Malware

Mal/Generic-S + Troj/Hancitor-T removal instruction

Malware Removal

The Mal/Generic-S + Troj/Hancitor-T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Hancitor-T virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

api.ipify.org
vidompleury.com
cobleignespos.ru

How to determine Mal/Generic-S + Troj/Hancitor-T?


File Info:

crc32: 804C31FA
md5: 9cc4b309c6512e3e518b908a3b405209
name: 9CC4B309C6512E3E518B908A3B405209.mlw
sha1: 22a3801a7d5af2a8c360100f54109665ad3c1dde
sha256: 3be8abd0e02fb6155a198949f8432fe2ad79dbe4134b288ff9284596ac1a9517
sha512: 6ce82d70b5ec5854e28d27495b40c04f250b3cf7625a63d0cc87da7d9e8cfda986a2c780381e04bf56be6375218d2daee36059cb9b84dc11ae894f34a9655599
ssdeep: 3072:LfZbc4nMmZLt0Zn9ne2hSzRH+pmgkSIidvRDjZQvEQib5P2V2B9mVCBnAf79uI0:CXmZLt0Znxe2UY/PhQhUP2Tg6f79uf
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999-2018
FileDescription: BASS
FileVersion: 2.4.14
CompanyName: Un4seen Developments
Translation: 0x0000 0x04b0

Mal/Generic-S + Troj/Hancitor-T also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Chanitor.59
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.355017
SangforSuspicious.Win32.Attribute.HighConfidence
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Hancitor.7a5fcb2c
K7GWTrojan ( 0057e6e21 )
K7AntiVirusTrojan ( 0057e6e21 )
CyrenW32/Trojan.JSKN-0396
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HLLQ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Malwarex-9874388-0
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderTrojan.GenericKD.46529269
MicroWorld-eScanTrojan.GenericKD.46529269
Ad-AwareTrojan.GenericKD.46529269
SophosMal/Generic-S + Troj/Hancitor-T
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.9cc4b309c6512e3e
EmsisoftTrojan.GenericKD.46529269 (B)
AviraTR/AD.ZDlder.cducl
Antiy-AVLTrojan/Generic.ASCommon.1F1
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Hancitor.RVC!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.46529269
AhnLab-V3Trojan/Win.Hancitor.R427158
McAfeeRDN/Generic.hbg
MAXmalware (ai score=85)
MalwarebytesTrojan.Chanitor
PandaTrj/CI.A
IkarusTrojan.Win32.Agent
FortinetW32/Kryptik.HLLQ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-S + Troj/Hancitor-T?

Mal/Generic-S + Troj/Hancitor-T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment