Trojan

Trojan:Win32/Chanitor.A removal

Malware Removal

The Trojan:Win32/Chanitor.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Chanitor.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Chanitor.A?


File Info:

name: CF9C2B6D072B56A268B0.mlw
path: /opt/CAPEv2/storage/binaries/4878d1b2ba3406fd403533077e7203710bb0af80f2b568d6db21d12d9ad2ea69
crc32: 288110E8
md5: cf9c2b6d072b56a268b00583a1133b8c
sha1: c42864a8e3b4587bc10c7704151331e061d6a8a7
sha256: 4878d1b2ba3406fd403533077e7203710bb0af80f2b568d6db21d12d9ad2ea69
sha512: 36cfe6063e58e52900e61648a6b04b6d29bd0bd512b351530ddc30fe059d6ce5b0a2bb97a2c5c1186991ee8e30a6a2b206dbba9e16f84e9c68aa3a9b900bfbb2
ssdeep: 1536:GuivFNkrWkkpH6UFSLGOEd8ZNiked8ctGSt3RxpO8E98p7R6FoU34OHCph7P3Q0:h2QikkBTCEd83AzdxbE98RR6uOHEc0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170A38D12B999C033D092513348AAD341573BBD2212368E57FB887BFD5FB06D15E2A39B
sha3_384: 20a36f037562f0b1ac0b65f2b5977bc2664fa2c47e042dee36bba01e866ad6093b26687f00270a73ef160d37d9e0c6a0
ep_bytes: e8813b0000e989feffff8bff558bec83
timestamp: 2014-09-29 12:12:34

Version Info:

CompanyName: ABCSoft Group
FileDescription: Graphics Remote Engine (32-bit)
FileVersion: 3.4.0.6
InternalName: Graphics Engine
LegalCopyright: Copyright (C) 2013 ABCSoft Group
OriginalFilename: remengine.exe
ProductName: Graphics Remote Engine (32-bit)
ProductVersion: 3.4.0.6
Translation: 0x0409 0x04b0

Trojan:Win32/Chanitor.A also known as:

LionicTrojan.Win32.Agentb.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.34792
MicroWorld-eScanTrojan.Agent.BFRI
FireEyeGeneric.mg.cf9c2b6d072b56a2
CAT-QuickHealTrojanPWS.Zbot.A5
McAfeeGeneric.zm
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.46921
SangforTrojan.Win32.Hancitor.8
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Chanitor.3c0d54d9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d072b5
BitDefenderThetaGen:NN.ZexaF.34182.gq0@aWrNDUbi
VirITTrojan.Win32.Generic.BUW
CyrenW32/Trojan.HGCZ-8191
SymantecW32.Extrat
ESET-NOD32Win32/TrojanDownloader.Hancitor.A
TrendMicro-HouseCallTROJ_HANCITOR.B
Paloaltogeneric.ml
ClamAVWin.Trojan.Generickd-924
KasperskyTrojan.Win32.Agentb.bter
BitDefenderTrojan.Agent.BFRI
NANO-AntivirusTrojan.Win32.Foreign.eopopx
AvastWin32:Trojan-gen
TencentWin32.Trojan.Agentb.Tcme
EmsisoftTrojan.Agent.BFRI (B)
ComodoMalware@#2w95j6cega0m2
F-SecureTrojan.TR/Ranyque.ygb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HANCITOR.B
McAfee-GW-EditionGeneric.zm
SophosML/PE-A + Troj/Agent-AJDG
JiangminTrojan/Generic.bahmo
WebrootW32.Malware.Gen
AviraTR/Ranyque.ygb
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Chanitor.A
ViRobotTrojan.Win32.Agent.101376.AM
ZoneAlarmTrojan.Win32.Agentb.bter
GDataWin32.Trojan.Agent.WVPC40
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.R120696
VBA32Hoax.Foreign
ALYacTrojan.Agent.BFRI
MalwarebytesMachineLearning/Anomalous.100%
APEXMalicious
YandexTrojan.Foreign!dOzADQHGoNo
IkarusTrojan-Downloader.Win32.Hancitor
eGambitUnsafe.AI_Score_82%
FortinetW32/Agent.VMG!tr
AVGWin32:Trojan-gen
PandaTrj/Chgt.I

How to remove Trojan:Win32/Chanitor.A?

Trojan:Win32/Chanitor.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment