Malware

Strictor.238880 (B) (file analysis)

Malware Removal

The Strictor.238880 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.238880 (B) virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Strictor.238880 (B)?


File Info:

crc32: 0B29EBF1
md5: aff330c3b007e8dfc65e48cc143fa023
name: pato.exe
sha1: 67b6a850b054edd5371669244dccbe801794f690
sha256: d5fc8b07eb527515f0c5beb5e3d66329a6183527fb2967657b3b49202c8452be
sha512: e95a3e3db8fd52bfd004b228ec7a167b295103b6cc92a1e41f64959b8c283302ccd173b7e0c678d23c544d39dc2818c9cadf72ec00433c90bc167b8d4ec986bb
ssdeep: 3072:+wdK6g8IT9xrv5UbCZqbjgdbI5RBYLF8bGGZxvaNOdWMc7WysffHxxbvDfGTf5b:fK6g8ITjgJWe708aGZxSv175shNvDOT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.9600.16384 (winblue_rtm.130821-1623)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16384
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Strictor.238880 (B) also known as:

MicroWorld-eScanGen:Variant.Strictor.238880
FireEyeGen:Variant.Strictor.238880
ALYacGen:Variant.Strictor.238880
SangforMalware
BitDefenderGen:Variant.Strictor.238880
Cybereasonmalicious.0b054e
APEXMalicious
GDataGen:Variant.Strictor.238880
Ad-AwareGen:Variant.Strictor.238880
EmsisoftGen:Variant.Strictor.238880 (B)
Endgamemalicious (high confidence)
ArcabitTrojan.Strictor.D3A520
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Malware/Win32.Generic.C2504380
MAXmalware (ai score=85)
ESET-NOD32a variant of MSIL/Kryptik.UGA
FortinetMSIL/Kryptik.UGA!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM41.1.E8B7.Malware.Gen

How to remove Strictor.238880 (B)?

Strictor.238880 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment