Malware

About “Strictor.43462” infection

Malware Removal

The Strictor.43462 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.43462 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Strictor.43462?


File Info:

name: 2F036640264BBF1EF01B.mlw
path: /opt/CAPEv2/storage/binaries/60175276142128c18fbac912cafa41e1cf4386cef83fe42367faf29a8a54c10b
crc32: 9DE13657
md5: 2f036640264bbf1ef01bf079d594fca2
sha1: 0b7711d13b265fec063915c0d9032f2ec081c5f9
sha256: 60175276142128c18fbac912cafa41e1cf4386cef83fe42367faf29a8a54c10b
sha512: 598510036f8ee1c5844928493f85745535d3718a767eb5dc4a87d37bdbb35b5b0e32cfd9aff25763bf08f5efcc89e294eee46183616a72ff99df6452a6a20047
ssdeep: 12288:pH7Wcjdc/r2sxxiPGGAOOPSXDV8ClgVYhX5FSsf8QA/:pbCj2sObHtqQ4QI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100D4AF12B7D740FADDA239701977E32BDB357518532AC9C7EFE02E628E111409B3A366
sha3_384: d5d708c8e401632390d217160eb6767cbd7387c3ee855fda8c60bfb13a3b3391d5f95ef294e5a024ba584a20ed868876
ep_bytes: e837c20000e979feffffcccccccccccc
timestamp: 2010-01-15 16:09:54

Version Info:

0: [No Data]

Strictor.43462 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.43462
FireEyeGeneric.mg.2f036640264bbf1e
CAT-QuickHealTrojan.AutoIT.Injector.A
McAfeeArtemis!2F036640264B
CylanceUnsafe
Cybereasonmalicious.0264bb
CyrenW32/AutoIt.TU.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.Autoit.R suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Strictor.43462
NANO-AntivirusTrojan.Win32.SMMM5506.dzruep
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Strictor.43462
EmsisoftGen:Variant.Strictor.43462 (B)
VIPREGen:Variant.Strictor.43462
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
GDataGen:Variant.Strictor.43462
AviraTR/Dropper.Gen
ArcabitTrojan.Strictor.DA9C6
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGen:Variant.Strictor.43462
MAXmalware (ai score=81)
RisingTrojan.Generic@AI.89 (RDML:WBS70FZzjdU+QheexGDfdg)
IkarusBackdoor.MSIL.Noancooe
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autoit.BXM!tr
BitDefenderThetaAI:Packer.1605201919
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Strictor.43462?

Strictor.43462 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment