Malware

Strictor.188722 malicious file

Malware Removal

The Strictor.188722 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.188722 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Strictor.188722?


File Info:

name: FF9147B8543D54AE5C57.mlw
path: /opt/CAPEv2/storage/binaries/ccc177a89e477258c8422d2d045f430d99e5d41804b72ef3546d54de14bce1a9
crc32: 9F95047E
md5: ff9147b8543d54ae5c5762f8f4ee25a8
sha1: a3296431e93be3d4bcb83fb12aec39ac26d55b7b
sha256: ccc177a89e477258c8422d2d045f430d99e5d41804b72ef3546d54de14bce1a9
sha512: e0ab3e3e700d3e32f25b748579e0d7cf99e96a711b015be741cdec100affb1da30f99f2729b78bfd96dd49238d31c2c3836863d23786277d2a43beea1d708d44
ssdeep: 24576:yAHnh+eWsN3skA4RV1Hom2KXMmHa+NP5:1h+ZkldoPK8Ya+j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109058B0273D2D036FFAB92739B6AB20196BD79250133852F13981DB9BD701B1277E663
sha3_384: 9c257ce6158e5b3c2f971af85d2b46ef7638bf0116554ddf870306bcf50fa901070319634d65d731e22857681b6f6966
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-31 02:38:26

Version Info:

Comments: NAgZfJ
CompanyName: eXDWNVJoALrIJcMewjJKyMYRKZU
FileDescription: DNIcbm
FileVersion: 75.27.90.68
InternalName: StVFbqteDcn
LegalCopyright: cAIQVrtZA
LegalTrademarks: IkvdtrJuZVtEU
ProductName: sxMYW
ProductVersion: 56.84.92.82
Translation: 0x0809 0x04b0

Strictor.188722 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.188722
FireEyeGen:Variant.Strictor.188722
ALYacGen:Variant.Strictor.188722
K7AntiVirusTrojan ( 0056a9891 )
BitDefenderGen:Variant.Strictor.188722
K7GWTrojan ( 0056a9891 )
Cybereasonmalicious.8543d5
CyrenW32/AutoIt.SR.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Autoit.OHY
APEXMalicious
KasperskyUDS:Trojan.Script.Generic
RisingTrojan.Runner/Autoit!1.C11B (CLASSIC)
Ad-AwareGen:Variant.Strictor.188722
SophosTroj/Autoit-DCS
ComodoMalware@#3xstzdnqxchy
TrendMicroTrojan.AutoIt.OTORUN.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Strictor.188722 (B)
GDataGen:Variant.Strictor.188722
AviraWORM/FakeExt.Gen8
MAXmalware (ai score=85)
ArcabitTrojan.Strictor.D2E132
ZoneAlarmHEUR:Trojan.Script.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!FF9147B8543D
MalwarebytesMalware.AI.1981923179
TrendMicro-HouseCallTrojan.AutoIt.OTORUN.SM
IkarusTrojan.Win32.Autoit
FortinetW32/Autoit.OHL!tr
AVGAutoIt:Runner-BH [Trj]
AvastAutoIt:Runner-BH [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Strictor.188722?

Strictor.188722 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment