Malware

About “Strictor.34346” infection

Malware Removal

The Strictor.34346 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.34346 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
zndlq.zuo45.com
ip.biyuhu.com

How to determine Strictor.34346?


File Info:

crc32: 5C75BA30
md5: 4265dd74f504eb495ab368323333aec1
name: cqwndlq.exe
sha1: 2652c84b26a4ea4e18c81f27b5bf8f65334779cc
sha256: f094217b56a5c78b7aa6579c7b9c26f7260a48bb4aaa00d8300e62405b6600b1
sha512: 616b9574be5fb87c17a38f76795e0c9a9d47375feea334fbfd077d4bba3adab75249f5605cbb4783318b11dbf53aabd5f7467a97a0d5f9426cb4e77e8b95d100
ssdeep: 98304:W/cm7/AEcQAZTLpJCVSfudD5QAVPKBTeLJSqdjjN/WebEgfPCpc:acFcAZhAVS2xpAeL4M5pP9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0804 0x03a8

Strictor.34346 also known as:

MicroWorld-eScanGen:Variant.Strictor.34346
FireEyeGen:Variant.Strictor.34346
McAfeeArtemis!4265DD74F504
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Strictor.34346
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Downloader-46660
GDataGen:Variant.Strictor.34346
Kasperskynot-a-virus:AdWare.Win32.Agent.xxdutf
AlibabaTrojan:Win32/Tiggre.333741d5
NANO-AntivirusTrojan.Win32.Hook.iaot
ViRobotTrojan.Win32.Z.Strictor.3813888
AegisLabTrojan.Multi.Generic.4!c
TencentMalware.Win32.Gencirc.10b84c6f
Endgamemalicious (moderate confidence)
SophosMal/BackDr-X
ComodoMalware@#3bqb46g5yles2
F-SecureAdware.ADWARE/Agent.cnzgd
BaiduWin32.Trojan.Legendmir.r
TrendMicroTROJ_SPNV.01CP14
McAfee-GW-EditionGeneric PUP.fx
EmsisoftGen:Variant.Strictor.34346 (B)
IkarusTrojan.Crypt
WebrootW32.Malware.Gen
AviraADWARE/Agent.cnzgd
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Strictor.D862A
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.xxdutf
ALYacGen:Variant.Strictor.34346
PandaTrj/CI.A
ESET-NOD32a variant of Generik.JQVJYSW
TrendMicro-HouseCallTROJ_SPNV.01CP14
RisingTrojan.Win32.Generic.1584978B (C64:YzY0OhG8T7vLHss9)
YandexTrojan.CFI!vI8ffml9Vyk
FortinetW32/Generik.IALYETH!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.4f504e
Paloaltogeneric.ml
MaxSecureTrojan.Malware.7164915.susgen

How to remove Strictor.34346?

Strictor.34346 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment