Malware

Strictor.172601 removal instruction

Malware Removal

The Strictor.172601 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.172601 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Strictor.172601?


File Info:

crc32: CAA7B1E2
md5: 2b7659d9407490d1a8a6fbb0860980fe
name: 2B7659D9407490D1A8A6FBB0860980FE.mlw
sha1: 21f72e23271a440f892543218ce2ae3278001dfa
sha256: 3d1b9bc3d00baf39096ff502c787a5f18e16c29b18f745f2ab8e59ffd32f8bc7
sha512: b8bd44a004640fa4b710589726c85b65a72730c3220cfba7d539e835f769697e92cc68531b4c5a5c7790a35ced02532082117d087045d5cf3a9487e0afea7a53
ssdeep: 49152:68zc5Y2wmaGqc3vCOFiXMZd8THjGMso3FCHajBAVwPtDATyGaDA/n3mKms:6Qc5WmNqc3vriXMZKnGMso34HaFAVmt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Oxford Nanopore Technologies. 1999 - 2014
CompanyName: Oxford Nanopore Technologies
PrivateBuild: 8.3.7.372
Comments: Pulling Davidsn Transitively Journaling
ProductName: Generic
ProductVersion: 8.3.7.372
FileDescription: Pulling Davidsn Transitively Journaling
OriginalFilename: Generic
Translation: 0x0409 0x04b0

Strictor.172601 also known as:

K7AntiVirusTrojan ( 0053c3dc1 )
DrWebTrojan.Encoder.3953
CynetMalicious (score: 99)
ALYacGen:Variant.Strictor.172601
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.181
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0053c3dc1 )
Cybereasonmalicious.940749
CyrenW32/Encoder.JSMC-3773
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKEA
ZonerTrojan.Win32.72081
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Encoder.mt
BitDefenderGen:Variant.Strictor.172601
NANO-AntivirusTrojan.Win32.Encoder.fhqynq
MicroWorld-eScanGen:Variant.Strictor.172601
TencentWin32.Trojan.Encoder.Hsss
Ad-AwareGen:Variant.Strictor.172601
SophosMal/Generic-S
ComodoMalware@#3ludiwotwzd7g
BitDefenderThetaGen:NN.ZexaCO.34796.Lr0@aG5eA3hi
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.2b7659d9407490d1
EmsisoftGen:Variant.Strictor.172601 (B)
AviraHEUR/AGEN.1118315
Antiy-AVLTrojan/Generic.ASMalwS.2821FE9
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Strictor.172601
McAfeeArtemis!2B7659D94074
VBA32BScope.TrojanRansom.Encoder
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.86 (RDML:7N+2rwtR+kWWHawrHugbig)
YandexTrojan.GenAsa!QOQeVnvhOGo
IkarusTrojan.Crypt
FortinetW32/Kryptik.GKEA!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Encoder.HwoCEpsA

How to remove Strictor.172601?

Strictor.172601 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment