Malware

Strictor.151892 (B) information

Malware Removal

The Strictor.151892 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.151892 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
srv1100.ru

How to determine Strictor.151892 (B)?


File Info:

crc32: 6683D0D9
md5: ffda3b9fd9b4e7887956d2336d1e6e25
name: FFDA3B9FD9B4E7887956D2336D1E6E25.mlw
sha1: 95a517f55a4f4005acb10394102d923cb5a792d2
sha256: d381e1d759eb484621f2b4895deae4d9d18ae95ca8d4f1cc3ddc6e06aca5f252
sha512: 9a5fd56394525a64c940f4c961a7ed0356f9fb0b1037d374a2e37b5ed0d9823134176d6246c54627edfae2602e08ec5a50bcaae4c1753503263944ec7bf74e89
ssdeep: 6144:LAsBZXxds+/rcs+Q5plvjlfz/V/41W3ldcjkm+V2a3RKTHgRlSW9ysJ:txd3/xnpl7Jd481dcUV2i8q4W8I
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Strictor.151892 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004d2c141 )
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Phorpiex-7581643-1
ALYacGen:Variant.Strictor.151892
ZillyaTrojan.Onion.Win32.462
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004d2c141 )
Cybereasonmalicious.fd9b4e
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Dropper-gen [Drp]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Strictor.151892
MicroWorld-eScanGen:Variant.Strictor.151892
TencentWin32.Trojan.Dropper.Eivi
Ad-AwareGen:Variant.Strictor.151892
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#374f1m3o4h68m
DrWebWin32.HLLW.Phorpiex.54
VIPREVirus.Win32.Sality.at (v)
TrendMicroRansom_Enestedel.R007C0DH921
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.ffda3b9fd9b4e788
EmsisoftGen:Variant.Strictor.151892 (B)
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.30D7E90
MicrosoftRansom:Win32/Enestedel.B!rfn
ArcabitTrojan.Strictor.D25154
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Strictor.151892
AhnLab-V3Trojan/Win32.Androm.R222321
McAfeeArtemis!FFDA3B9FD9B4
MAXmalware (ai score=82)
MalwarebytesMalware.AI.4186448567
TrendMicro-HouseCallRansom_Enestedel.R007C0DH921
RisingTrojan.Generic@ML.86 (RDMK:btdJbeQQF3gAoHoEpMLMjg)
IkarusWorm.Win32.AutoRun
FortinetW32/Generic.BTX!tr
AVGWin32:Dropper-gen [Drp]
Qihoo-360HEUR/QVM42.0.26FB.Malware.Gen

How to remove Strictor.151892 (B)?

Strictor.151892 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment