Trojan

About “Trojan:Win32/Hancitor.ARK!MTB” infection

Malware Removal

The Trojan:Win32/Hancitor.ARK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Hancitor.ARK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

api.ipify.org
maduabin.com
thenexames.ru
pritursivers.ru

How to determine Trojan:Win32/Hancitor.ARK!MTB?


File Info:

crc32: 5ADF734F
md5: b0b16d046655871f9a452e2c34d062e5
name: B0B16D046655871F9A452E2C34D062E5.mlw
sha1: ad92e7b5e1eb1a1c16d4c0cb1a23b1eeb124a7ee
sha256: 5660be89b90aa88fc81719220933e8bcc5ead56352eac7f5ea4a053cb575db8a
sha512: fd48003beb2df843cb6471e4864eb770b490cc7d9359f69c2551f367b840595773e7778f924c210975f1aead0bb7892f2fa547f5d15b36d9d16e9c12fe3228a7
ssdeep: 6144:WEitiibyyCeTbC2dRAMT8gz84XP10aGXohw50VHkf/t3VT38Z6VDfSYn0J:WPiiemC2P3Bd1pJhw5EHkf13VbIkqC0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Six old 1995-2015 Boardinterest
FileVersion: 3.4.0.573
CompanyName: Six old
Stay: Ever object
ProductVersion: 3.4.0.573
FileDescription: Legstore
ProductName: Legstore
OriginalFilename: complete.dll
Translation: 0x0409 0x04e4

Trojan:Win32/Hancitor.ARK!MTB also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Johnnie.295930
ALYacTrojan.Agent.Hancitor
SangforMalware
BitDefenderGen:Variant.Johnnie.295930
ArcabitTrojan.Johnnie.D483FA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
Ad-AwareGen:Variant.Johnnie.295930
F-SecureTrojan.TR/Kryptik.xdzeq
DrWebTrojan.Chanitor.59
TrendMicroTrojan.Win32.MALREP.THLOIBO
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Johnnie.295930
EmsisoftGen:Variant.Johnnie.295930 (B)
WebrootW32.Trojan.Gen
AviraTR/Kryptik.xdzeq
MAXmalware (ai score=80)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Hancitor.ARK!MTB
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataGen:Variant.Johnnie.295930
CynetMalicious (score: 100)
McAfeeRDN/Hancitor
VBA32BScope.TrojanBanker.Cridex
MalwarebytesSpyware.MassLogger
ESET-NOD32a variant of Win32/GenKryptik.EYBL
TrendMicro-HouseCallTrojan.Win32.MALREP.THLOIBO
RisingTrojan.Generic@ML.90 (RDML:f8Eizix+kbfanr6xWOun9w)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.EYBL!tr
AVGFileRepMalware

How to remove Trojan:Win32/Hancitor.ARK!MTB?

Trojan:Win32/Hancitor.ARK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment