Malware

About “Strictor.148805” infection

Malware Removal

The Strictor.148805 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.148805 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Strictor.148805?


File Info:

crc32: DA8DA102
md5: 3fd87d0b4e31c79599ad8c10bac54ba2
name: rabochiy_chit_na_warface_fd3-d87___.exe
sha1: a004981689997fe2ccafba72184638a83136a1ad
sha256: f65beaf261fe200488bb25b11df594ec665e34ee707072bf91964fe6fabc54fb
sha512: 5ed3046bbc6edab413c5fc08011c4b6c337614de0a6352a9afc4edfe1e9aaed808a40ff22a4a6f2d163801ffc82535d17ccab4418f50b653118268c17c94a531
ssdeep: 24576:rJq0MNvT8dKsllU84N2nb+NDe15Qd5ZbxKlt+Tt7J/:rJql9TOh4fDePQLZbxTt7J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
ProductVersion: 1, 0, 20, 1745
FileVersion: 1, 0, 20, 1745
ProductName: JSON XML Parcer Application
Translation: 0x0409 0x04b0

Strictor.148805 also known as:

MicroWorld-eScanGen:Variant.Strictor.148805
FireEyeGeneric.mg.3fd87d0b4e31c795
McAfeePacked-LZ.d!3FD87D0B4E31
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00518b421 )
BitDefenderGen:Variant.Strictor.148805
K7GWTrojan ( 00518b421 )
Cybereasonmalicious.b4e31c
TrendMicroTROJ_GEN.R002C0PEG19
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Strictor.148805
Kasperskynot-a-virus:HEUR:AdWare.Win32.FileTour.gen
AlibabaTrojan:Win32/Kryptik.263e3851
NANO-AntivirusTrojan.Win32.GenKryptik.etizgo
RisingTrojan.Generic@ML.99 (RDMK:CrYQtaOlFNYJ43KkVb72Ww)
Ad-AwareGen:Variant.Strictor.148805
SophosMal/Generic-S
ComodoApplication.Win32.Bundler.BDE@6p0op3
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.LoadMoney.2499
ZillyaAdware.FileTour.Win32.47908
Invinceaheuristic
McAfee-GW-EditionPacked-LZ.d!3FD87D0B4E31
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.148805 (B)
SentinelOneDFI – Malicious PE
JiangminAdWare.FileTour.kwy
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/Win32.AdLoad
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.FileTour.gen
MicrosoftSoftwareBundler:Win32/Ogimant
AhnLab-V3Adware/Win32.AdLoad.C2189486
ALYacGen:Variant.Strictor.148805
VBA32Malware-Cryptor.Kirgudu
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FXPH
TrendMicro-HouseCallTROJ_GEN.R002C0PEG19
TencentWin32.Trojan.Falsesign.Lplw
YandexPUA.AdLoad!
IkarusPUA.LoadMoney
FortinetW32/GenKryptik.AWMO!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Virus.Adware.d36

How to remove Strictor.148805?

Strictor.148805 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment