Trojan

Trojan:Win32/Hanictor!MSR removal instruction

Malware Removal

The Trojan:Win32/Hanictor!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Hanictor!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

api.ipify.org
thotainizent.com
hrowedinizoin.ru
traverso.ru

How to determine Trojan:Win32/Hanictor!MSR?


File Info:

crc32: 87299132
md5: dd4a0430f7d2ae88218ae20d7f534b5a
name: DD4A0430F7D2AE88218AE20D7F534B5A.mlw
sha1: 686affda83e86aeb66214745837efe44b16d3c19
sha256: 0bf26a2b47b66b6f1091a99b59933ad8ba0bda3783501d9eea7a032bceea2cbb
sha512: 3e173f15b552452028115908bf128cdb8500cdb171fb965a9fcaf1cfa6682cd44a592bf1a1473d119cb5f8de6b6009629afd66ab30ffc11b1d2cda61cc0fe238
ssdeep: 3072:pCdDLdrxuSlWxK65tLdgiMGLapEOSs5eu2LiN3VYc+cQXgqjIe6jI5p702IihM+:pCdDLzDWVLdgiVrsNBTmMeD5d02IM6
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Wife total Corporation. All rights reserved
InternalName: Neck
FileVersion: 5.5.1.863
CompanyName: Wife total Corporation
ProductName: Wife totalxae Form scalexae
ProductVersion: 5.5.1.863 Keepstream
FileDescription: Wife total Form scale
OriginalFilename: hope.dll
Translation: 0x0409 0x04b0

Trojan:Win32/Hanictor!MSR also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Chanitor.59
CynetMalicious (score: 99)
ALYacTrojan.Agent.Hancitor
SangforSuspicious.Win32.Attribute.HighConfidence
CrowdStrikewin/malicious_confidence_60% (W)
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HKZC
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:Trojan.Win32.Agent.a
BitDefenderTrojan.GenericKD.36928964
MicroWorld-eScanTrojan.GenericKD.36928964
Ad-AwareTrojan.GenericKD.36928964
SophosML/PE-A
ComodoTrojWare.Win32.UMal.qpqxb@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36928964
EmsisoftTrojan.GenericKD.36928964 (B)
SentinelOneStatic AI – Suspicious PE
AviraW97M/Agent.250971
MicrosoftTrojan:Win32/Hanictor!MSR
GDataTrojan.GenericKD.36928964
McAfeeArtemis!DD4A0430F7D2
MAXmalware (ai score=89)
MalwarebytesTrojan.Hancitor
RisingTrojan.GenKryptik!8.AA55 (C64:YzY0OnE7BrK6KFIw)
IkarusWin32.Outbreak
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Hanictor!MSR?

Trojan:Win32/Hanictor!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment