Malware

Strictor.151892 removal

Malware Removal

The Strictor.151892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.151892 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

srv1100.ru

How to determine Strictor.151892?


File Info:

crc32: 855E939C
md5: edf79e96bb639e659075cf9c13efa917
name: EDF79E96BB639E659075CF9C13EFA917.mlw
sha1: 2af64e356b4ceae50a120b1466a40ee76da77e24
sha256: b1adb56d1560d23db849a2e982ec35f6aac455685fe05074d76ad2e0147cc016
sha512: b77a864dc4b6a9ce3969c7ae239310688682303df3a9016882c392b9ddb2692e71b22a7b3d483603bb72466d853060465ce3d759eb8d2506b403f35f7c290333
ssdeep: 6144:dAsBZXxds+/rcs+Q5plvjlfz/V/4kXwV2zAowUAbgRlSW9ysJ:rxd3/xnpl7Jd4kXwVSAQj4W8I
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Strictor.151892 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004cf69f1 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Phorpiex.54
CynetMalicious (score: 99)
ALYacGen:Variant.Strictor.151892
CylanceUnsafe
ZillyaTrojan.Onion.Win32.462
SangforRansom.Win32.Enestedel.B!rsm
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Enestedel.c0f3a975
K7GWTrojan ( 004cf69f1 )
Cybereasonmalicious.6bb639
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Phorpiex-7581643-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Strictor.151892
NANO-AntivirusTrojan.Win32.Phorpiex.exyvlr
MicroWorld-eScanGen:Variant.Strictor.151892
TencentWin32.Trojan.Agent.Apwp
Ad-AwareGen:Variant.Strictor.151892
SophosMal/Generic-R + Mal/Cerber-Z
VIPREVirus.Win32.Sality.at (v)
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.edf79e96bb639e65
EmsisoftGen:Variant.Strictor.151892 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.30D7E90
MicrosoftRansom:Win32/Enestedel.B!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Strictor.151892
AhnLab-V3Trojan/Win32.Androm.R222321
McAfeeGeneric.dad
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4186448567
PandaTrj/CI.A
RisingTrojan.Generic@ML.86 (RDMK:btdJbeQQF3gAoHoEpMLMjg)
FortinetW32/Generic.BTX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HyoDEpsA

How to remove Strictor.151892?

Strictor.151892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment