Malware

Should I remove “Strictor.173071”?

Malware Removal

The Strictor.173071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.173071 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

Related domains:

a.tomx.xyz

How to determine Strictor.173071?


File Info:

crc32: 1247B2FB
md5: 056c1c5f7c2b569f1df1d050cf7fee7d
name: 056C1C5F7C2B569F1DF1D050CF7FEE7D.mlw
sha1: 731c9c8ebe3a24d4767509cc316d11a6e9979d01
sha256: aea7df55e5b6c953134e54023245349bbb59a7d8952c0ee49f7f19d5cc941f55
sha512: 3ba7f7702c7891c1fd27723cbc33c8804452398c9cce0872f36aaf29c2bbd7b2fb80e26d4b71bac5779bc5bf9317c6e3fa93f4aafc7600fa0208cbce8b7caac8
ssdeep: 98304:24TzEpuKgPqX7pO525SD39MyyN5CiMy57ABtxDjKrOMYXmIH:24U8/p52O39MhCN0B4H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: www.xiaodao.la
FileVersion: 1.0.0.0
CompanyName: QQxff1a253957
Comments: www.xiaodao.la
ProductName: www.xiaodao.la
ProductVersion: 1.0.0.0
FileDescription: www.xiaodao.la
Translation: 0x0804 0x04b0

Strictor.173071 also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.307
MicroWorld-eScanGen:Variant.Strictor.173071
ALYacGen:Variant.Strictor.173071
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b8e1b1 )
BitDefenderGen:Variant.Strictor.173071
K7GWAdware ( 004b8e1b1 )
Cybereasonmalicious.f7c2b5
BitDefenderThetaGen:NN.ZexaF.34574.@B0@a4010chb
CyrenW32/Trojan.GEVI-8853
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.AJ potentially unwanted
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Mbro.bcej
ViRobotTrojan.Win32.Z.Strictor.6762496
RisingRansom.Mbro!8.1E1F (CLOUD)
Ad-AwareGen:Variant.Strictor.173071
SophosGeneric PUA HD (PUA)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.056c1c5f7c2b569f
EmsisoftGen:Variant.Strictor.173071 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Strictor.173071
MAXmalware (ai score=85)
KingsoftWin32.Troj.Generic.a.(kcloud)
ArcabitTrojan.Strictor.D2A40F
ZoneAlarmTrojan-Ransom.Win32.Mbro.bcej
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R366900
Acronissuspicious
McAfeeArtemis!056C1C5F7C2B
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H09BI21
YandexTrojan.GenAsa!QsoJOFSe/Nw
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_94%
FortinetRiskware/FlyStudio_Packed
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HxMB22oA

How to remove Strictor.173071?

Strictor.173071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment