Categories: Malware

Should I remove “Strictor.26789”?

The Strictor.26789 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.26789 virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Strictor.26789?


File Info:

crc32: 28D7BF1Amd5: 324e0fef77979b12316e70b0fc27d0bcname: 5-2-46-636.exesha1: 32ecfe92a862a1addc38e815654c0b6ab22b510bsha256: d1ca34f1567de130c39275a0a3411b13a3efd57bf5b4819aa8343a13298a3a35sha512: 8b3f89efdef7a7a33ad7fcd0e9a448438b733472e25393e1c12b5ead967a050c8ff1ed4cb230340bfd4947a5cf359c8d0c71695e9167d3dac28b2d4c1485f2d2ssdeep: 1536:KlDeiKE3hY5t1Lle0vawCOtSgiXpcUBp:73/1Ze8BBtw5ZBptype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2002InternalName: DDialerFileVersion: 1, 0, 0, 1CompanyName: PrivateBuild: LegalTrademarks: Comments: ProductName: DDialerSpecialBuild: ProductVersion: 1, 0, 0, 1FileDescription: DDialerOriginalFilename: DDialer.exeTranslation: 0x0407 0x04b0

Strictor.26789 also known as:

MicroWorld-eScan Gen:Variant.Strictor.26789
FireEye Generic.mg.324e0fef77979b12
CAT-QuickHeal Dialer.Porndialer.29871
McAfee Dialer-RAS.at.gen.a
Cylance Unsafe
VIPRE BehavesLike.Win32.Malware.bsc (vs)
Sangfor Malware
K7AntiVirus Dialer ( 000f9fde1 )
BitDefender Gen:Variant.Strictor.26789
K7GW Dialer ( 000f9fde1 )
Cybereason malicious.f77979
Invincea heuristic
F-Prot W32/Webdialer.gen!GSA
TotalDefense Win32/Dialer.FQ
APEX Malicious
Avast Win32:Dialer-gen2 [Trj]
ClamAV Win.Trojan.Dialer-39
GData Gen:Variant.Strictor.26789
Kaspersky not-a-virus:Porn-Dialer.Win32.eConnect
Alibaba RiskWare:Win32/eConnect.8bbd2b92
NANO-Antivirus Trojan.Win32.Online.crbezk
AegisLab Riskware.Win32.Generic.l0jn
Rising Trojan.RasDialer!1.66EA (CLOUD)
Ad-Aware Gen:Variant.Strictor.26789
Emsisoft Gen:Variant.Strictor.26789 (B)
Comodo ApplicUnwnt.Win32.PornDialer.Agent.~Q@2ml6f
F-Secure Dialer.DIAL/000333
DrWeb Dialer.Premium.224
Zillya Dialer.eConnect.Win32.2
TrendMicro DIAL_RAS.HE
McAfee-GW-Edition Dialer-RAS.at.gen.a
CMC Porn-Dialer.Win32!O
Sophos Dial/190-A
Ikarus Dialer
Cyren W32/Webdialer.gen!GSA
Jiangmin Porn-Dialer.Generic.fx
Avira DIAL/000333
MAX malware (ai score=88)
Antiy-AVL GrayWare[Porn-Dialer]/Win32.eConnect
Endgame malicious (high confidence)
Arcabit Trojan.Strictor.D68A5
SUPERAntiSpyware Trojan.Agent/Gen-Dialer
ZoneAlarm not-a-virus:Porn-Dialer.Win32.eConnect
Microsoft Program:Win32/Vigram.A
AhnLab-V3 Trojan/Win32.Dialer.R9857
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34090.dmKfaSTf6CD
ALYac Gen:Variant.Strictor.26789
VBA32 BScope.Dialer.Premium
Panda Dialer.Gen
ESET-NOD32 a variant of Win32/Dialer.0190-Dialers
TrendMicro-HouseCall DIAL_RAS.HE
Tencent Malware.Win32.Gencirc.10b58508
Yandex Dialer.eConnect.Gen
SentinelOne DFI – Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Riskware/190
Webroot W32.Dialer.Gen
AVG Win32:Dialer-gen2 [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 HEUR/QVM11.1.54B5.Malware.Gen

How to remove Strictor.26789?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Risktool.Flystudio.16024 removal tips

The Risktool.Flystudio.16024 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Trojan.Generic.34363382 removal tips

The Trojan.Generic.34363382 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Should I remove “AIT:Trojan.Nymeria.4438”?

The AIT:Trojan.Nymeria.4438 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

What is “Malware.AI.2428723483”?

The Malware.AI.2428723483 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Tedy.551777 (file analysis)

The Tedy.551777 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “Lazy.518842” infection

The Lazy.518842 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago