Malware

How to remove “Strictor.2098”?

Malware Removal

The Strictor.2098 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.2098 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Strictor.2098?


File Info:

name: 35A2356F6FF63EDA41C9.mlw
path: /opt/CAPEv2/storage/binaries/079139fca5652e8235add5bdabf94e06f58cbdbc3d424e671e702eaadaf79289
crc32: 54BEEE75
md5: 35a2356f6ff63eda41c97cd260de08f8
sha1: 6557dadbaa43e41f5d33c0d46eaf50e7e2a6715c
sha256: 079139fca5652e8235add5bdabf94e06f58cbdbc3d424e671e702eaadaf79289
sha512: 90a7883a3ef67bfb2dba9f84dd25ce26cc9b0341e2f3e34a7ba5a8b9023214c96f4ce6d96f32206b96fce99fd383209cfaea66b7d452c0ec1232c15ce6b035b5
ssdeep: 6144:Yd38DlqL/iGy6wdqHLKRHoF9ck+CzeJuHR8iAoNbc5+4z4z45nGgyXVhPlmXetJE:YalqmP6wdSKRHA+1ePc534s4gEHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C594015EE90104B3C4A0D07181FA8A512BBA5C1B7677893FEBE4F94DCCF138489665BE
sha3_384: 925a921d168ef9f395da305d588260eb740bedac6bab1eecd8e4cafe4453b6f297e97b682e392ec28550382c709ac02d
ep_bytes: 558bec6aff68d834400068fa22400064
timestamp: 2010-05-13 16:06:06

Version Info:

Comments:
CompanyName:
FileDescription: 800 x 600 JPEG
FileVersion: 0, 0, 0, 0
InternalName:
LegalCopyright: 版权所有 (C) 2010
LegalTrademarks:
OriginalFilename: 800 x 600 JPEG
PrivateBuild:
ProductName: 800 x 600 JPEG
ProductVersion: 0, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Strictor.2098 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.2098
FireEyeGeneric.mg.35a2356f6ff63eda
SkyhighBehavesLike.Win32.Pate.gc
McAfeeGenericRXFD-ZY!35A2356F6FF6
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Strictor.2098
SangforSuspicious.Win32.Save.ins
K7AntiVirusBackdoor ( 00173d0f1 )
BitDefenderGen:Variant.Strictor.2098
K7GWBackdoor ( 00173d0f1 )
Cybereasonmalicious.baa43e
BitDefenderThetaGen:NN.ZexaF.36792.zq1@a89RdMdb
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/TrojanDropper.Demekaf.A
APEXMalicious
ClamAVWin.Trojan.Genpack-9758826-0
KasperskyTrojan.Win32.Agent.xfzn
NANO-AntivirusTrojan.Win32.Baidu.iidnc
ViRobotTrojan.Win32.A.PSW-Magania.1913020.A
RisingTrojan.Win32.Fednu.tpm (CLASSIC)
SophosMal/Behav-103
BaiduWin32.Backdoor.Zegost.a
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebTrojan.PWS.Siggen1.27425
TrendMicroBKDR_ZEGOST.SM34
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.2098 (B)
IkarusTrojan.Win32.Jorik
JiangminBackdoor/Agent.ckeb
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.CFI.Gen
VaristW32/Dropper.AH.gen!Eldorado
Antiy-AVLTrojan/Win32.Zegost
Kingsoftmalware.kb.a.994
MicrosoftBackdoor:Win32/Farfli.FT!MTB
XcitiumBackdoor.Win32.Agent.~Avvn@1vvdru
ArcabitTrojan.Strictor.D832
ZoneAlarmTrojan.Win32.Agent.xfzn
GDataGen:Variant.Strictor.2098
CynetMalicious (score: 100)
AhnLab-V3Dropper/Agent.81977
VBA32Trojan.Agent
ALYacGen:Variant.Strictor.2098
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM34
TencentTrojan.Win32.Agent.tj
YandexTrojan.GenAsa!6eb5W7mjQtc
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Shodi.I
FortinetW32/Mdrop.CPG!tr
AVGWin32:GenMalicious-ION [Trj]
AvastWin32:GenMalicious-ION [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Strictor.2098?

Strictor.2098 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment