Malware

Strictor.218251 (B) removal

Malware Removal

The Strictor.218251 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.218251 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Strictor.218251 (B)?


File Info:

name: 35C04D20D968D950E5E6.mlw
path: /opt/CAPEv2/storage/binaries/c38ab9175f737d1252283c3a2cc8b9e596311900409d4fdcc7023bb8faf0a5f0
crc32: 2D9D85DD
md5: 35c04d20d968d950e5e6d0c3dbc6f862
sha1: 5a227048d58e3b314d0d6007a63959869038886b
sha256: c38ab9175f737d1252283c3a2cc8b9e596311900409d4fdcc7023bb8faf0a5f0
sha512: 0fa64600324f54ded33968b2a2c60f69b26c31370868cbeea65faa8149bc828ead2a82345104ea8e42133419965d061617bd6bccbd9b26e9138cca803040b878
ssdeep: 24576:dMzGLzXCFEzGLvMzGLzCLzXCFEz3XCFEzGLvMzGL9zGLzCLzXCFM:dP7GnvPu7GSGnvPku7GM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F65120EA341E637D6D8707BDB49C6F5C331A8250E2EEB1722E8BC5F3BD21674122995
sha3_384: 5bdfc7911a982ddcd73377db7111d71b5f6595d26e08aca6da189117984ed342ea97ca58918089aec502618589e7d353
ep_bytes: 60be00a046008dbe0070f9ffc787a420
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Strictor.218251 (B) also known as:

DrWebBackDoor.Click.1197
MicroWorld-eScanGen:Variant.Strictor.218251
FireEyeGeneric.mg.35c04d20d968d950
McAfeeGenericRXAA-AA!35C04D20D968
CylanceUnsafe
ZillyaRootkit.Xanfpezes.Win32.18
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.0d968d
BitDefenderThetaGen:NN.ZelphiF.34062.wnJfa4bcgBeb
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Strictor.218251
NANO-AntivirusTrojan.Win32.Xanfpezes.ctohhu
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Strictor.218251
EmsisoftGen:Variant.Strictor.218251 (B)
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Buzus
GDataGen:Variant.Strictor.218251 (2x)
JiangminRootkit.Xanfpezes.i
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4CE60
KingsoftHeur.SSC.2786352.1216.(kcloud)
ArcabitTrojan.Strictor.D3548B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32Rootkit.Xanfpezes
ALYacGen:Variant.Strictor.218251
MAXmalware (ai score=85)
MalwarebytesMalware.AI.16635435
APEXMalicious
YandexRootkit.LAHHDTE!4stLbCQ4Sv4
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Click.1197!tr.bdr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Strictor.218251 (B)?

Strictor.218251 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment