Malware

Strictor.134653 (file analysis)

Malware Removal

The Strictor.134653 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.134653 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Strictor.134653?


File Info:

name: 9E805B53BDD562B8E104.mlw
path: /opt/CAPEv2/storage/binaries/ca0c4b7613c2e5e0b3e59c60b4b05608b279bf92b9d4f8b4e8b8e8fdbb9c521a
crc32: FF18CEC5
md5: 9e805b53bdd562b8e104859c7991ec22
sha1: ceb6f8f0c5d17fb2e749ca6810499305913b5d22
sha256: ca0c4b7613c2e5e0b3e59c60b4b05608b279bf92b9d4f8b4e8b8e8fdbb9c521a
sha512: 4a15b5433f649ea101cb938fed8cc68c34bd6ece1ddc5531d2d48eb798dd647a33d56194d37b08842d4a1de0ef2d1ed5e0cb7dc0d3434c4636187d0803ad195a
ssdeep: 12288:zozGdX0M4ornOmZIzfMwHHQmRROXKZVEl6OGWxa:z4GHnhIzOaSU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8F43B1A7EA1CC40F88B82B6C51D16F967237E1CC36A741796AB3ED83B756AC0B5103D
sha3_384: 306054b81ec53beed87594e97d2d77fe75ee32cd9c8ff0c056876c0b4d253a6d0e3b6e3253a8f6b1a690d21d7f4a7fbe
ep_bytes: 60be00404e008dbe00d0f1ff57eb0b90
timestamp: 2017-10-20 10:34:21

Version Info:

FileVersion: 22.4.1.9850
Comments: SolidShare.Net Unattended Installer
FileDescription: SolidShare.Net Unattended Installer
ProductVersion: 22.4.1.9850
LegalCopyright: © 2017 By Progressive
CompanyName: SolidShare TEAM
ProductName: Acronis True Image
Translation: 0x0409 0x04b0

Strictor.134653 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Strictor.134653
FireEyeGeneric.mg.9e805b53bdd562b8
McAfeeArtemis!9E805B53BDD5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005146da1 )
AlibabaTrojan:Win32/Qhost.c52de95d
K7GWTrojan ( 005146da1 )
Cybereasonmalicious.3bdd56
CyrenW32/FakeDoc.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Qhost.PMA
Paloaltogeneric.ml
CynetMalicious (score: 99)
BitDefenderGen:Variant.Strictor.134653
NANO-AntivirusTrojan.Win32.Qhost.eurmfk
AvastWin32:Malware-gen
TencentWin32.Trojan.Qhost.Hwwe
Ad-AwareGen:Variant.Strictor.134653
EmsisoftApplication.Silentall (A)
ComodoMalware@#3svf4jzjr8fy2
ZillyaTrojan.Qhost.Win32.18400
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bh
SophosMal/Generic-S
GDataWin32.Riskware.Shasoli.A
AviraTR/Qhost.ymgcn
MAXmalware (ai score=99)
APEXMalicious
MicrosoftTrojan:Win32/Occamy.CCA
AhnLab-V3Malware/Win32.Generic.C2343642
ALYacGen:Variant.Strictor.134653
MalwarebytesPUP.Optional.Progressive
IkarusRiskware.Win32.Ekisoli
FortinetW32/Qhost.PMA!tr
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Strictor.134653?

Strictor.134653 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment