Malware

Strictor.179313 malicious file

Malware Removal

The Strictor.179313 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.179313 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Strictor.179313?


File Info:

name: 382D972CB1B137DA2673.mlw
path: /opt/CAPEv2/storage/binaries/2db5f360e70537da7c2f64c46b12b94e4e7379c288cc3d617771422338d2d7ed
crc32: 6A316D94
md5: 382d972cb1b137da267330c0540d0372
sha1: 033faf30158c80d1c2ef909f1c4c674c914ba15c
sha256: 2db5f360e70537da7c2f64c46b12b94e4e7379c288cc3d617771422338d2d7ed
sha512: ca02d75bd289a9e4cd184fc5b1c9c18abeeca1832d16a053fac0adf67e5e63504890b83f610ad91df2ec760f4ad1862147123f5be3e9e0c86f5fdec7d2dc7446
ssdeep: 196608:z0QBZAmNy2CBwBl2kXXrfesDmzeD7hheVvbJ/S3hBvIDxiQvjyEzkJ5m:z012KwrWHWPYbFwLvmiQvjyEY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F66331928EE8B4EE134E730FA7168B6BCCA493961705E3C71D9FF48609A145C522F9F
sha3_384: f6978c70360462622033036074995218e40abc4e92b66c27bc853faf71211b2a29c01990faa4c7b24cda0aa97b8f12ee
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2019-12-26 03:46:36

Version Info:

FileVersion: 1.0.0.0
FileDescription: SETUP 基础类驱动应用程序
ProductName: 加密狗驱动
ProductVersion: 1.0.0.0
CompanyName: 加密狗驱动
LegalCopyright: 加密狗驱动
Comments: 加密狗驱动
Translation: 0x0804 0x04b0

Strictor.179313 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.179313
FireEyeGeneric.mg.382d972cb1b137da
CylanceUnsafe
VIPREGen:Variant.Strictor.179313
AlibabaTrojan:Win32/GenKryptik.61bfcd3a
Cybereasonmalicious.cb1b13
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.DVJQ
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Strictor.179313
TencentWin32.Trojan.Agen.Uwhl
Ad-AwareGen:Variant.Strictor.179313
SophosGeneric ML PUA (PUA)
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.179313 (B)
IkarusTrojan-PWS.Win32.QQPass
GDataGen:Variant.Strictor.179313
AviraHEUR/AGEN.1231421
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32BScope.Trojan.Bitrep
ALYacGen:Variant.Strictor.179313
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!UFR5fVmKjrs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34646.@B0baarueyeb

How to remove Strictor.179313?

Strictor.179313 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment