Categories: Malware

Strictor.231497 removal

The Strictor.231497 file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Strictor.231497 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Strictor.231497?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: TROJ_GEN.R002C0WKC19

File Info:

Name: meka.exe

Size: 733184

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: a43f97001dc5180e1c72da7d6affb244

SHA1: ba1f12b8186500da82d11698442224f2278a8231

SH256: 41b0dc912fc6f643bf2719b826acaa159143b637d435379463a959ad97db2d14

Version Info:

[No Data]

Strictor.231497 also known as:

ALYac Spyware.LokiBot
APEX Malicious
AVG Win32:CrypterX-gen [Trj]
Ad-Aware Gen:Variant.Strictor.231497
AegisLab Trojan.Win32.Crypt.4!c
AhnLab-V3 Malware/Win32.Generic.C3558899
Alibaba Trojan:Win32/GenKryptik.d350366b
Antiy-AVL Trojan/Win32.Crypt
Arcabit Trojan.Strictor.D38849
Avast Win32:CrypterX-gen [Trj]
Avira TR/Kryptik.qqobb
BitDefender Gen:Variant.Strictor.231497
Comodo Malware@#1g6q1opjkqi0m
CrowdStrike win/malicious_confidence_60% (W)
Cylance Unsafe
Cyren W32/Injector.BMXR-4774
DrWeb Trojan.PWS.Stealer.27390
ESET-NOD32 a variant of Win32/Injector.EIVT
F-Prot W32/Injector.IOL
F-Secure Trojan.TR/Kryptik.qqobb
FireEye Generic.mg.a43f97001dc5180e
Fortinet W32/GenKryptik.DXIV!tr
GData Win32.Trojan-Stealer.LokiBot.J9HX18
Ikarus Trojan.Inject
K7AntiVirus Trojan ( 0055b3a11 )
K7GW Trojan ( 0055b3a11 )
Kaspersky HEUR:Trojan.Win32.Crypt.gen
MAX malware (ai score=100)
Malwarebytes Trojan.MalPack.SMY.Generic
MaxSecure Trojan.Malware.10374761.susgen
McAfee GenericRXJB-OW!A43F97001DC5
McAfee-GW-Edition BehavesLike.Win32.Fareit.bc
MicroWorld-eScan Gen:Variant.Strictor.231497
Microsoft Trojan:Win32/Skeeyah.A!MTB
NANO-Antivirus Trojan.Win32.Palevo.ggyeyu
Paloalto generic.ml
Panda Trj/GdSda.A
Rising Trojan.Generic@ML.81 (RDML:7Q1Z0ILZA9WuwJfHw1oNcQ)
Sophos Mal/Generic-S
Symantec Trojan Horse
Trapmine suspicious.low.ml.score
TrendMicro TROJ_GEN.R002C0WKC19
TrendMicro-HouseCall TROJ_GEN.R002C0WKC19
VBA32 TScope.Trojan.Delf
VIPRE Trojan.Win32.Generic!BT
Webroot W32.Trojan.Gen
Yandex Trojan.Crypt!T/VwjYG/BwQ
ZoneAlarm HEUR:Trojan.Win32.Crypt.gen

How to remove Strictor.231497?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan:Win32/Remcos!pz (file analysis)

The Trojan:Win32/Remcos!pz is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

About “Jalapeno.1619” infection

The Jalapeno.1619 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Babar.213996 removal tips

The Babar.213996 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Malware.AI.2248263649 (file analysis)

The Malware.AI.2248263649 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

About “Trojan.Dropper.Agent.AKK” infection

The Trojan.Dropper.Agent.AKK is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago