Malware

Strictor.282047 removal instruction

Malware Removal

The Strictor.282047 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.282047 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Strictor.282047?


File Info:

name: 333B5807695F5F66C5E0.mlw
path: /opt/CAPEv2/storage/binaries/88e90da1940875f30ef70bff819dd027654226141b4589d268340fd7e2908054
crc32: 29E8E0D6
md5: 333b5807695f5f66c5e083201a347297
sha1: e1c183fadeb3a00cd035c7456b4f435b7472bf7b
sha256: 88e90da1940875f30ef70bff819dd027654226141b4589d268340fd7e2908054
sha512: 4aae67432a58b8cc53434ebc6b1c8d0cc99d91fe680da524e33c33eba577173e68d90212ac2c7bd0d0a427fc466a7575e3c0a835c2adedb9dfdcd9b3976a6bee
ssdeep: 49152:4BkgabzPS4LgM04eHscpydqNB9C2O8jY93emD46TweL/PtuXHjXDGiiKbQx+xnvo:IpOP/+/UU4wu/PwXDXD0CCBnbAO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13036AE213A42C03AE9A10171967DEBBA586D7A310F3590D7E3C82F6F19709D37A36E17
sha3_384: c8aebbe08a8c3c3592601e276c3398387963e258ab4949d1638a80eabf213b9eadfe6fdf7527dae4cbb84a3dbe17cf2d
ep_bytes: e8ed060000e925feffffc3558bec8b45
timestamp: 2023-07-26 03:13:49

Version Info:

FileDescription: 鲁大师 硬件防护中心
FileVersion: 5.1023.2400.726
InternalName: ComputerZTray
LegalCopyright: 版权所有 (C) 2008-2023 www.ludashi.com
OriginalFilename: ComputerZTray.exe
ProductName: 鲁大师 硬件防护中心
ProductVersion: 5.1023.2400.726
Translation: 0x0409 0x04b0

Strictor.282047 also known as:

LionicTrojan.Win32.Ludashi.4!c
DrWebTrojan.DownLoader45.64027
MicroWorld-eScanGen:Variant.Strictor.282047
FireEyeGen:Variant.Strictor.282047
SkyhighArtemis
ALYacGen:Variant.Strictor.282047
Cylanceunsafe
VIPREGen:Variant.Strictor.282047
BitDefenderGen:Variant.Strictor.282047
K7GWAdware ( 005a42db1 )
K7AntiVirusAdware ( 005a42db1 )
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Ludashi.A potentially unwanted
NANO-AntivirusTrojan.Win32.Ludashi.jyaajj
RisingPUF.Ludashi!8.17698 (TFE:5:uyMZpSNRJkO)
SophosQihoo 360-related low reputation certificate (PUA)
EmsisoftGen:Variant.Strictor.282047 (B)
MAXmalware (ai score=85)
ArcabitTrojan.Strictor.D44DBF
GDataGen:Variant.Strictor.282047
AhnLab-V3Malware/Win.Generic.R601507
McAfeeArtemis!333B5807695F
DeepInstinctMALICIOUS
MalwarebytesPUP.Optional.ChinAd.DDS
IkarusPUA.Ludashi
MaxSecureAdware.W32.Burden.gen_246358
FortinetRiskware/Ludashi
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Strictor.282047?

Strictor.282047 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment