Trojan

Should I remove “Trojan:Win32/Hancitor.AL!MTB”?

Malware Removal

The Trojan:Win32/Hancitor.AL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Hancitor.AL!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ipify.org
spardethe.com
tworkityre.ru
shwashate.ru

How to determine Trojan:Win32/Hancitor.AL!MTB?


File Info:

crc32: F8463970
md5: 42280c09d96e719e86b78954f99534f3
name: 42280C09D96E719E86B78954F99534F3.mlw
sha1: 18b4c70fd62940e60fcd3a097e7c347ceb7f7590
sha256: 3191fd599a6738f152f95c0badb73598623b760b2171addf5aeb85b633e98450
sha512: b1e3570f5033c25a50ee9a6c766d835d3b166352d2e23b89e75fad843784dac5ec1824b69d5f0f3129e83378b7930df9843927b8b7544c4745b967671a958c6f
ssdeep: 12288:Eddg9hxdcS6+Zred2uwlOa9dM6PeI3x/:EdMRc1+ZqdxaNhx
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Large direct Corporation. All rights reserved
InternalName: Born Believe
FileVersion: 6.4.3.441
CompanyName: Large direct Corporation
Plant: EverBlue
ProductName: Large directxae Inchmeatxae
ProductVersion: 6.4.3.441
FileDescription: Large direct Inchmeat
OriginalFilename: double.dll
Translation: 0x0409 0x04b0

Trojan:Win32/Hancitor.AL!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Chanitor.59
MicroWorld-eScanGen:Variant.Zusy.355247
FireEyeGen:Variant.Zusy.355247
ALYacTrojan.Agent.Hancitor
SangforMalware
K7AntiVirusTrojan ( 005747151 )
BitDefenderGen:Variant.Zusy.355247
K7GWTrojan ( 005747151 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.HKFB-7415
SymantecTrojan.Gen.2
TrendMicro-HouseCallTrojan.Win32.MALREP.THLOIBO
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
AlibabaTrojanBanker:Win32/Hancitor.810a6b52
AegisLabTrojan.Win32.Cridex.7!c
Ad-AwareGen:Variant.Zusy.355247
EmsisoftGen:Variant.Zusy.355247 (B)
F-SecureTrojan.TR/Crypt.Agent.bpbqw
TrendMicroTrojan.Win32.MALREP.THLOIBO
McAfee-GW-EditionRDN/Hancitor
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.bpbqw
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Hancitor.AL!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Zusy.D56BAF
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataWin32.Trojan.Agent.95VG3F
CynetMalicious (score: 85)
McAfeeRDN/Hancitor
MAXmalware (ai score=83)
VBA32BScope.Trojan.Agentb
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIDQ
RisingTrojan.Generic@ML.81 (RDMK:KrLOivQSU59Ijr6IgWWzpA)
FortinetW32/GenKryptik.EYCS!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM40.1.D147.Malware.Gen

How to remove Trojan:Win32/Hancitor.AL!MTB?

Trojan:Win32/Hancitor.AL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment