Ransom

Ransom.Strictor.14 removal

Malware Removal

The Ransom.Strictor.14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Strictor.14 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Iraq)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom.Strictor.14?


File Info:

crc32: 597A2E51
md5: 4fe282522965681cc68a81866292113e
name: 4FE282522965681CC68A81866292113E.mlw
sha1: f59e2a12b1ed4bed6241f0e2fca9b77a3f7f6c0c
sha256: 90718f930046250f6ae41c9069533271c9171c053332ebd78273a2f1bff2cb00
sha512: 72f5292b1627b688275f0a927919a89f3774944f92318cce01e07c809525783d25c28a45f9db358fd831ee6a65c7336d4b47a661feddf5fc23c643458ceb3c92
ssdeep: 12288:PBEJrXuWhKo5yM5QVuXDgmRKEAekO17D33w6fWoQ42CJ4hKU46gZtmSFFIvllah:6JaaFQGQggyVp18sQ4ShMZASFFQn
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.Strictor.14 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.DownLoader9.43701
CynetMalicious (score: 85)
ALYacGen:Variant.Ransom.Strictor.14
CylanceUnsafe
ZillyaBackdoor.Xtreme.Win32.13408
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaBackdoor:Win32/Xtreme.3627df5c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.229656
CyrenW32/Trojan.ITSH-2961
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Remtasu.F
APEXMalicious
TotalDefenseWin32/Tnega.RSLUYMB
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Xtreme.arxz
BitDefenderGen:Variant.Ransom.Strictor.14
NANO-AntivirusTrojan.Win32.Androm.dnqrwy
ViRobotBackdoor.Win32.S.Xtreme.875008
MicroWorld-eScanGen:Variant.Ransom.Strictor.14
TencentWin32.Backdoor.Bp-fakems.Tnkq
Ad-AwareGen:Variant.Ransom.Strictor.14
ComodoMalware@#hhbb3t21t4sd
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FORUCON.BME
McAfee-GW-EditionRDN/Generic.bc
FireEyeGen:Variant.Ransom.Strictor.14
EmsisoftGen:Variant.Ransom.Strictor.14 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Xtreme.bye
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1129031
eGambitGeneric.Malware
MicrosoftBackdoor:Win32/Xtrat.AC
ArcabitTrojan.Ransom.Strictor.14
GDataGen:Variant.Ransom.Strictor.14
AhnLab-V3Backdoor/Win32.Xtreme.R130406
McAfeeRDN/Generic.bc
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FORUCON.BME
RisingBackdoor.Xtreme!8.25A (CLOUD)
YandexBackdoor.Xtreme!9cFFnOu5LI4
IkarusBackdoor.Win32.Xtreme
FortinetW32/Injector.COBZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Xtreme.HgIASOUA

How to remove Ransom.Strictor.14?

Ransom.Strictor.14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment