Malware

What is “Strictor.179379”?

Malware Removal

The Strictor.179379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.179379 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Strictor.179379?


File Info:

crc32: 509EEDA7
md5: dcaf0e4d91a7e8a994ce7b14f43caa42
name: DCAF0E4D91A7E8A994CE7B14F43CAA42.mlw
sha1: 9ce3878199e3a300929da2f1699cf018a603341f
sha256: 5b51b82ab3298d5c0cb2cf852f1275c0b1dbd6741e7c10df0a5b27499738a1ab
sha512: 12864b17b41933a2ca67142780d6311545c479814b058a256a74ce96c80fabecf6a77d4279c99f6b36a3e710e0f432a539a35f5e334dc04588e984dfb3321037
ssdeep: 12288:BMydzQCFwHFz6lD9piPoFDjj5epR4iQEXI9EO2T7liWr5OcSC1EF5xR:5R/Fw96XE4Dj1YR4GrSF5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000
InternalName: DDaemon
FileVersion: 4.11
CompanyName: Remote Access Technologies
PrivateBuild:
LegalTrademarks:
Comments: Remote Access Technologies DDaemon
ProductName: DDaemon
SpecialBuild:
ProductVersion: 4.11
FileDescription: DDaemon
OriginalFilename: DDaemon.exe
Translation: 0x0409 0x04b0

Strictor.179379 also known as:

DrWebTrojan.MulDrop8.14375
ALYacGen:Variant.Strictor.179379
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
Cybereasonmalicious.d91a7e
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Strictor.179379
NANO-AntivirusTrojan.Win32.Mlw.fahkqa
MicroWorld-eScanGen:Variant.Strictor.179379
TencentWin32.Trojan.Generic.Wurf
Ad-AwareGen:Variant.Strictor.179379
SophosMal/Generic-S
ComodoMalware@#15jg1vu6lbcjt
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Strictor.179379
EmsisoftGen:Variant.Strictor.179379 (B)
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24F42B1
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Riskware.Daemon.B
AhnLab-V3Malware/Win32.Generic.C2474370
McAfeeArtemis!DCAF0E4D91A7
MAXmalware (ai score=81)
VBA32BScope.Trojan.MulDrop
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
YandexTrojan.GenAsa!cSjd7Oim9y4
FortinetW32/Generic!tr
AVGWin32:Malware-gen

How to remove Strictor.179379?

Strictor.179379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment