Malware

Strictor.139267 removal

Malware Removal

The Strictor.139267 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.139267 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Strictor.139267?


File Info:

name: E195D3D5065C599F29F1.mlw
path: /opt/CAPEv2/storage/binaries/b79a112964cfc50ade34ee52b63fcebe6be862befede20c8a77cbc6930adfadc
crc32: CDF11819
md5: e195d3d5065c599f29f15d88e8c76846
sha1: f49aa6bd0297d706be8aba04e49eed30e3ca3538
sha256: b79a112964cfc50ade34ee52b63fcebe6be862befede20c8a77cbc6930adfadc
sha512: e354023730957e73dc2f8ee86aa799f15dbdad206a3eada5974e7028fa9d87efa09c6f37f92f14c144b33d3e77171126f9d24e2e75dd0e8cfee956e004bd0eef
ssdeep: 6144:hXPUFe11Z3/KO9n6w1AVCRX1loSY48CA4T:BUFe1nH96w1yC1foSYYA4T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8341247E1256A22D5B207748ECF8BD42A1CADA5544C897252FBE53F9C78720FB13F28
sha3_384: 424e893c84919b03fb0365d7627a5b2599fd8f3957ea108c81814cb94250c6832dcfe0cb66d680a3f2ab974000d26ef0
ep_bytes: 60be00c044008dbe0050fbff5789e58d
timestamp: 2019-10-09 14:19:03

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 宜宾易游网络科技有限公司
FileDescription: OA远程插件
ProductName: OA远程插件
FileVersion: 3.05.0010
ProductVersion: 3.05.0010
InternalName: 58OA
OriginalFilename: 58OA.exe

Strictor.139267 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strictor.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.139267
FireEyeGeneric.mg.e195d3d5065c599f
CAT-QuickHealTrojan.Agent
ALYacGen:Variant.Strictor.139267
Cylanceunsafe
SangforTrojan.Win32.Agent.V7p9
K7AntiVirusTrojan ( 004bcce71 )
K7GWTrojan ( 004bcce71 )
Cybereasonmalicious.5065c5
BitDefenderThetaGen:NN.ZevbaF.36662.omKfa4sokfpb
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Strictor.139267
AvastWin32:Malware-gen
RisingTrojan.Casur!8.10E51 (CLOUD)
EmsisoftGen:Variant.Strictor.139267 (B)
VIPREGen:Variant.Strictor.139267
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Strictor.139267
Antiy-AVLGrayWare/Win32.Unwaders
ArcabitTrojan.Strictor.D22003
MicrosoftProgram:Win32/Wacapew.C!ml
McAfeeArtemis!E195D3D5065C
MAXmalware (ai score=87)
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CHT23
MaxSecureTrojan.Malware.8328450.susgen
FortinetW32/Generic_PUA_PE
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Strictor.139267?

Strictor.139267 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment