Malware

Should I remove “Strictor.19923”?

Malware Removal

The Strictor.19923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.19923 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.

Related domains:

smtp.gmail.com
automation.whatismyip.com
googlemailer.3owl.com

How to determine Strictor.19923?


File Info:

crc32: A074F3FB
md5: bf7cc8763449fd1a5dbbadb7b28e5823
name: BF7CC8763449FD1A5DBBADB7B28E5823.mlw
sha1: 2c0fdb6fd9b753613c2d81d2642e6285991d6515
sha256: 4c88efb977ec8c998dfc3acae4c08d02f4960a063a336485e8e1712188f12a98
sha512: 3e22fdc7ea7238da9e91383908d8f99ec72710cc78dc16a7745b5cfe201da1da34f3d3138adf8f506c5b642d66b99eddbedb98a80f493e2100744f7187b9d207
ssdeep: 1536:MvGTpqD3kx79NYws6+qRMSR5I/2bvF92duNkB7PL3SPN400zaBC6PcyD6hnJ9BV:Miqzkd9NYV6TMSR5e2L2E+jCPx0zMC6
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Base.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Base.exe

Strictor.19923 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.7639
CynetMalicious (score: 99)
ALYacGen:Variant.Strictor.19923
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.63449f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.PD
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Blocker.dfyz
BitDefenderGen:Variant.Strictor.19923
NANO-AntivirusTrojan.Win32.DarkKomet.dcgqdr
MicroWorld-eScanGen:Variant.Strictor.19923
TencentWin32.Trojan.Blocker.Pitw
Ad-AwareGen:Variant.Strictor.19923
SophosMal/Generic-S
ComodoMalware@#inb5ukgt8o98
BitDefenderThetaAI:Packer.D5199FE71F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.bf7cc8763449fd1a
EmsisoftGen:Variant.Strictor.19923 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.izd
AviraTR/Crypt.CFI.Gen
eGambitUnsafe.AI_Score_100%
KingsoftWin32.HeurC.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Dynamer!dtc
AegisLabWorm.Win32.Palevo.li5k
ZoneAlarmTrojan-Ransom.Win32.Blocker.dfyz
GDataGen:Variant.Strictor.19923
McAfeeArtemis!BF7CC8763449
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Strictor!+lg5jHi4Q70
IkarusTrojan-Spy.MSIL
FortinetMSIL/Injector.AQK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Strictor.19923?

Strictor.19923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment