Malware

About “Strictor.258849” infection

Malware Removal

The Strictor.258849 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.258849 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Strictor.258849?


File Info:

crc32: 34D574F8
md5: 7f9b1a5c2a8036e2cbe9a83f12037cef
name: 7F9B1A5C2A8036E2CBE9A83F12037CEF.mlw
sha1: e2cd9c833106633964252f8241844a0b74ad6345
sha256: bac945aa0c4c42d3efd60b4192a27281ca06c48239d6e404ef6cefbe45483085
sha512: d20d660ecc72fb6838c6d06f7c14c5f5a8ddf051fee425895f9a0dbd9ae5177a460fa741811030b17b927f6c96df65785bd4de94a29c39d5e73ae1a3581533fb
ssdeep: 12288:qyaNaIYMpB44qDt4qEMeAle4q0PIbNhxm358CfTORrytP7kfPCnzJ9Ql6SdCKTS8:qyyaMAgMeOPIbNhxm358CSReBYsDMoA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Copyright xa9 2011 Nikyts software - Informxe1tica e tecnologia
InternalName: Project2
FileVersion: 1.00.0004
CompanyName: Nikyts software
LegalTrademarks: Nelson do Carmo
Comments: www.nikyts.com
ProductName: VBMovieManager
ProductVersion: 1.00.0004
FileDescription: VBMovieManager.exe
OriginalFilename: Project2.exe

Strictor.258849 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebBackDoor.Comet.3412
CynetMalicious (score: 99)
CAT-QuickHealPUA.WacapewVMF.S20642302
ALYacGen:Variant.Strictor.258849
CylanceUnsafe
ZillyaBackdoor.DarkKomet.Win32.49089
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaRansom:Win32/GandCrypt.00227853
K7GWRiskware ( 0040eff71 )
CyrenW32/VB.HE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FEHU
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
KasperskyTrojan-Ransom.Win32.GandCrypt.jmz
BitDefenderGen:Variant.Strictor.258849
NANO-AntivirusTrojan.Win32.Androm.iutfmi
MicroWorld-eScanGen:Variant.Strictor.258849
TencentMalware.Win32.Gencirc.10ce7dba
Ad-AwareGen:Variant.Strictor.258849
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34050.Ln2@aCU0ctN
TrendMicroRansom_GandCrypt.R002C0PGM21
McAfee-GW-EditionGenericRXOI-IF!7F9B1A5C2A80
FireEyeGen:Variant.Strictor.258849
EmsisoftGen:Variant.Strictor.258849 (B)
JiangminTrojan.GandCrypt.anu
AviraBDS/DarkKomet.iyani
Antiy-AVLTrojan/Generic.ASMalwS.32C9E49
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.Strictor.D3F321
GDataGen:Variant.Strictor.258849
AhnLab-V3Trojan/Win.Generic.R430621
McAfeeGenericRXOI-IF!7F9B1A5C2A80
MAXmalware (ai score=80)
VBA32Backdoor.DarkKomet
MalwarebytesVobfus.Worm.Evasion.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_GandCrypt.R002C0PGM21
YandexBackdoor.DarkKomet!lu2fxBuK2Eg
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FEHU!tr
AVGWin32:KeyloggerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HgIASY4A

How to remove Strictor.258849?

Strictor.258849 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment