Malware

What is “Strictor.135042”?

Malware Removal

The Strictor.135042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.135042 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Strictor.135042?


File Info:

crc32: 3DF921DE
md5: 4a3d8fcb19d2e2e78ada736a4e0356c6
name: 4A3D8FCB19D2E2E78ADA736A4E0356C6.mlw
sha1: 307a3abe7918d9ba74af3024a89b0d68efbdf71b
sha256: 8e3507a3b16619b93fd980aa7778df2ca3df6dc46d9d045509c7ff0bdfbd12b1
sha512: 382efa11d6212bf73712e0a019ba2ae8c7e0a070e268107ce6a7f9e6c2ed0ed75b92c6eff49fd80ebb95f6c958e4b902df5c0b79c5ab9abd7944ca7dea475704
ssdeep: 6144:d9VDzPi5HNbx6bVvsYUkkbM9D2nDr6gNrEH7OX:NaHNsJvsIADr6OrEHK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: DSno xa9 xID
Assembly Version: 6.6.5.6
InternalName: ficken.exe
FileVersion: 4.3.4.8
CompanyName: sKvzaOMG
LegalTrademarks: gvOiCvlR
Comments: NNBmOkwL
ProductName: XVrNlrnz
ProductVersion: 4.3.4.8
FileDescription: UQFZQHUe
OriginalFilename: ficken.exe

Strictor.135042 also known as:

K7AntiVirusTrojan ( 004431e51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 90)
ALYacGen:Variant.Strictor.135042
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.c4c962bc
K7GWTrojan ( 004431e51 )
Cybereasonmalicious.b19d2e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/UBGBot.C
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.jzjk
BitDefenderGen:Variant.Strictor.135042
NANO-AntivirusTrojan.Win32.Blocker.enwuih
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp
MicroWorld-eScanGen:Variant.Strictor.135042
TencentWin32.Trojan.Blocker.Pcsz
Ad-AwareGen:Variant.Strictor.135042
SophosML/PE-A + Mal/MsilDrop-B
ComodoMalware@#2bfxo33mozocb
BitDefenderThetaAI:Packer.B070FB7B1D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4a3d8fcb19d2e2e7
EmsisoftGen:Variant.Strictor.135042 (B)
SentinelOneStatic AI – Malicious PE
AviraBDS/Backdoor.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Strictor.D20F82
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Strictor.135042
McAfeeArtemis!4A3D8FCB19D2
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.524137461
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!aHV2Vlv5RZc
IkarusTrojan.MSIL.Crypt
FortinetMSIL/MsilDrop.B!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.27e

How to remove Strictor.135042?

Strictor.135042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment