Malware

What is “Strictor.164301”?

Malware Removal

The Strictor.164301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.164301 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Strictor.164301?


File Info:

name: 8944529DB10E84A50F96.mlw
path: /opt/CAPEv2/storage/binaries/4faf11b5f475183394377d55cc7ebf2e272e4fd994b0ca42d5c11f5ef9b00876
crc32: FF0F111D
md5: 8944529db10e84a50f9656f383b4920a
sha1: 10c154779c8e29723bab384e9802ab119e5cba72
sha256: 4faf11b5f475183394377d55cc7ebf2e272e4fd994b0ca42d5c11f5ef9b00876
sha512: b51ffa843a852a15d0b8da5490afca77080bcf7152f22c8dcee50b44eac673f5979a8e8f63ec4f1ef5f67481142154cb2fdb2886a4447d10c2285268d91d4c7b
ssdeep: 98304:RdnVnPC0sH1mNQjCQM7Bv5f+dyvDHwkW2R:H1a0i1CQjCQABhf+gHwwR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153E5121263DD83E1C3726133BA65BB01BEBB7C2546A1F59B2FC9093DED20161921E673
sha3_384: 806829b34fcffe937b21f7c9542168109f64f7a841eaf8c71b2fc468844205550775cf337399e5f691310f842451b591
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2014-03-11 21:57:32

Version Info:

Translation: 0x0809 0x04b0

Strictor.164301 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.me6H
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.57088
MicroWorld-eScanGen:Variant.Strictor.164301
FireEyeGeneric.mg.8944529db10e84a5
ALYacGen:Variant.Strictor.164301
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055e39b1 )
AlibabaTrojan:Win32/AutInject.7a887563
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.db10e8
BitDefenderThetaAI:Packer.A783C65D19
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_BLOCKER.AG
Paloaltogeneric.ml
ClamAVWin.Dropper.Nanocore-9234893-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Variant.Strictor.164301
NANO-AntivirusTrojan.Script.Agent.debxaj
AvastAutoIt:Injector-HA [Trj]
TencentWin32.Trojan.Dropper.Eanc
SophosTroj/Malit-FE
ComodoMalware@#bxfbd9vn0l6
TrendMicroTROJ_BLOCKER.AG
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Strictor.164301 (B)
JiangminTrojan.Autoit.gzx
AviraDR/AutoIt.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Strictor.164301
CynetMalicious (score: 100)
McAfeeArtemis!8944529DB10E
MAXmalware (ai score=100)
VBA32Trojan.Autoit.Wirus
MalwarebytesBackdoor.Bladabindi
APEXMalicious
FortinetW32/Fynloski.AM!tr
AVGAutoIt:Injector-HA [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Strictor.164301?

Strictor.164301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment