Malware

Strictor.249537 removal tips

Malware Removal

The Strictor.249537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.249537 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects the presence of Wine emulator via function name
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects information about installed applications
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

orbitalcucumbers.top
borrowme.top

How to determine Strictor.249537?


File Info:

crc32: E83A5B8A
md5: 2ce0cee5f3d1d1f7464b080214e60acf
name: 2CE0CEE5F3D1D1F7464B080214E60ACF.mlw
sha1: cb6f7f21a45a8f799e7a25479e0bf1fdeceb7e1b
sha256: 5b54b4edfc05210d6ed77ecbe6501861d8bd903c401c2aae1021573ff271c03b
sha512: 63bb4c4e8c98d248421c0bebe6ff0b5a2211941b708ac046f24ab1f0dc4cef6efa0cd850a13a148c02231e8c2bf1a0cf5600aae168e3563278b8fd0a44d95f87
ssdeep: 49152:AmXejRETmQQuYV0060xGc/uGZ66YBDABFBw474U5pQMm3bqtKGJA2tvDtmTsxDED:AmX6RUJQZV2yGclbYhABFn7HYMm3bqti
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Strictor.249537 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.249537
FireEyeGeneric.mg.2ce0cee5f3d1d1f7
CAT-QuickHealTrojan.Agent
McAfeeGenericRXGB-RT!2CE0CEE5F3D1
ZillyaAdware.InstMonster.Win32.162
SangforMalware
K7AntiVirusUnwanted-Program ( 0051b9171 )
BitDefenderGen:Variant.Strictor.249537
K7GWUnwanted-Program ( 0051b9171 )
Cybereasonmalicious.5f3d1d
CyrenW32/InstallMonster.JJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Malware.Agent-6598770-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusTrojan.Win32.InstallMonster.eupoxh
TencentMalware.Win32.Gencirc.10b30eb2
Ad-AwareGen:Variant.Strictor.249537
EmsisoftGen:Variant.Strictor.249537 (B)
ComodoApplication.Win32.InstallMonster.TN@7g2wfa
F-SecureHeuristic.HEUR/AGEN.1116974
DrWebTrojan.InstallMonster.2398
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosInstall Monster (PUA)
Ikarusnot-a-virus:AdWare.InstallMonster
JiangminAdWare.DLBoost.fnyl
AviraHEUR/AGEN.1116974
Antiy-AVLTrojan[Packed]/Win32.Dico
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Strictor.D3CEC1
ZoneAlarmPacked.Win32.Dico.gen
GDataWin32.Application.InstallMonstr.V
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.InstMonster.R211604
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34804.3oHfaiY5Gwki
ALYacGen:Variant.Strictor.249537
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/InstallMonstr.UD potentially unwanted
YandexTrojan.GenAsa!OvcV+SUmHBE
SentinelOneStatic AI – Malicious PE – Installer
eGambitUnsafe.AI_Score_98%
FortinetW32/Agen.AAAF!tr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Virus.Adware.b78

How to remove Strictor.249537?

Strictor.249537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment