Malware

Strictor.101213 (file analysis)

Malware Removal

The Strictor.101213 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.101213 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Strictor.101213?


File Info:

crc32: 023EE4E3
md5: 0ec0f77ff47788fe0b6ac0702d6e35f2
name: 0EC0F77FF47788FE0B6AC0702D6E35F2.mlw
sha1: 9deebd2c0f26e2f0cd779d305fd58713066292ca
sha256: 8750ad4813f215b6401531136577f635bded5df13acab7227aeb7bb9b9e3deb6
sha512: e911267897ed4a8222c4cfeca1f1fe28c733d5b264f0fb70af9e06919e0e0a7b994523819ca3be4c4ae5c1c7878f6f3984ded3bc4021cb0d1f68db66021800ed
ssdeep: 98304:5mJZWgry+d0m4hWzuZJPPfqcNJYSVLUjH5oxFbxx:5818mCnfqiJtVUjZEdx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 Adobe Systems Incorporated. All rights reserved.
InternalName: Adobe Download Manager
FileVersion: 2.0.0.120s
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Download Manager
ProductVersion: 2.0.0.120s
FileDescription: Adobe Download Manager
OriginalFilename: Adobe Download Manager
Translation: 0x0409 0x04b0

Strictor.101213 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.101213
FireEyeGeneric.mg.0ec0f77ff47788fe
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericR-JIP!0EC0F77FF477
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Strictor.101213
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ff4778
BitDefenderThetaGen:NN.ZexaF.34804.fx0@a8mefQii
CyrenW32/Ditertag.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Salgorea.AS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-9764479-0
NANO-AntivirusTrojan.Win32.Salgorea.emdims
TencentBackdoor.Win32.Finfish.b
Ad-AwareGen:Variant.Strictor.101213
EmsisoftGen:Variant.Strictor.101213 (B)
ComodoBackdoor.Win32.Finfish.ct@94xved
F-SecureHeuristic.HEUR/AGEN.1117294
ZillyaTrojan.Salgorea.Win32.27
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosML/PE-A + Troj/Agent-BGCI
SentinelOneStatic AI – Malicious PE – Downloader
JiangminBackdoor.Finfish.ae
AviraHEUR/AGEN.1117294
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Strictor.D18B5D
AhnLab-V3Malware/Win32.Generic.C2187753
ZoneAlarmHEUR:Backdoor.Win32.Finfish.vho
GDataGen:Variant.Strictor.101213
CynetMalicious (score: 100)
Acronissuspicious
VBA32Backdoor.Finfish
MAXmalware (ai score=84)
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Finfish!8.192 (TFE:5:xsaFnaNFiqD)
YandexTrojan.GenAsa!Vl/tO0Uk9tE
IkarusTrojan.Win32.Salgorea
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.3D5023!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.08A1.Malware.Gen

How to remove Strictor.101213?

Strictor.101213 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment