Malware

Strictor.248626 removal

Malware Removal

The Strictor.248626 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.248626 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Strictor.248626?


File Info:

name: 9E70BF95AA5B148B5C8E.mlw
path: /opt/CAPEv2/storage/binaries/c781eec81259bfbb7ba01eab9ed739c7960b83495516a9f7026bb61bbfc321a3
crc32: A2C24D98
md5: 9e70bf95aa5b148b5c8ede84cf72b14c
sha1: 86e6420d2d61f7a1a664b1661e342d149143cee4
sha256: c781eec81259bfbb7ba01eab9ed739c7960b83495516a9f7026bb61bbfc321a3
sha512: 5f14f6da72d1ecab9524081a633bb2134a17096fd4bd07cccc819d9d2ee88946587a34211e7d02452227a8212fe9da0707c09fdcb8a3dcb2bfe3b3e8ce0ca38d
ssdeep: 12288:gTZ4KP36Q/6Vya612XE3GsKexoYEHomvy8/8IZzSDx9mkp:giKPV/8moUVBlEIMJ3w73
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12BE40110F5D1E032D4B3053189A9CAB56A68FF21CB214DEF3BD80D5B7F282D1A935AD6
sha3_384: d34a1f68cb169c0c12d60702798bbbd2f6ee8989556615f220b5447f80eb3a68eb99d3848e035b40f45e657921230348
ep_bytes: e8fd030000e987feffff558bec6a00ff
timestamp: 2018-01-21 12:09:58

Version Info:

0: [No Data]

Strictor.248626 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Generic.2!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Strictor.248626
FireEyeGeneric.mg.9e70bf95aa5b148b
CAT-QuickHealSwBundler.Prepscram.A7
SkyhighBehavesLike.Win32.FakeAVSecurityTool.jc
McAfeePUP-XDV-WE
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
AlibabaAdWare:Win32/StartSurf.8d27fa12
K7GWTrojan ( 0051707e1 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPNR
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Strictor.248626
NANO-AntivirusRiskware.Win32.StartSurf.exfuib
SUPERAntiSpywareAdware.IStartSurf/Variant
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!8.8 (TFE:5:iCt3vkZ3ypT)
EmsisoftGen:Variant.Strictor.248626 (B)
F-SecureHeuristic.HEUR/AGEN.1316944
DrWebTrojan.Vittalia.14470
VIPREGen:Variant.Strictor.248626
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Crypt
MAXmalware (ai score=99)
GDataGen:Variant.Strictor.248626
JiangminAdWare.StartSurf.ama
WebrootW32.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1316944
VaristW32/S-1795aaa5!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
KingsoftWin32.Troj.StartSurf.gen
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
ArcabitTrojan.Strictor.D3CB32
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftSoftwareBundler:Win32/Prepscram
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R218853
BitDefenderThetaGen:NN.ZexaF.36744.QuW@aeyvbflk
ALYacGen:Variant.Strictor.248626
VBA32Trojan.Vittalia
Cylanceunsafe
PandaTrj/Genetic.gen
TencentWin32.AdWare.Generic.Bzlw
YandexTrojan.GenAsa!acsDT6jNDkU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FWQG!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.d2d61f
DeepInstinctMALICIOUS

How to remove Strictor.248626?

Strictor.248626 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment