Malware

What is “Strictor.260337”?

Malware Removal

The Strictor.260337 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.260337 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Strictor.260337?


File Info:

name: 48ECDFA5E10802FA0DB8.mlw
path: /opt/CAPEv2/storage/binaries/84ac68480b52fe16a8ea29563997e686b5e05aba9ab5f19872f30e4464242957
crc32: 0BDA417F
md5: 48ecdfa5e10802fa0db847395086e42e
sha1: 742e965357e072a2c455252a980e486e98ed41d9
sha256: 84ac68480b52fe16a8ea29563997e686b5e05aba9ab5f19872f30e4464242957
sha512: 2bf88cd350cfc97c88ddfa4f0450dcdf3bdb11f5197c95ceb5be55f31007c9d46932e80dbddc6cb32c23f39cdbdb035b778eeac209a67ce121292a617fa4e99c
ssdeep: 3072:Q88VmJIrJT6WOwwTuTSWOscaFJAaS5tWleAnFf5dq6gMcjP2B+Oz:Q88VysxwTuTjKC9Rm2B+Oz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116044909B4F0D028D8A195B57998E9954828FEB0C42839533FC13B6B5F784DEC97AF63
sha3_384: 38472dd8883ca4cd07ea371d4ff5565f337332806722c86836682c117261cc53d47db22d0a754d64965ed2806c97974d
ep_bytes: e86d020000e98efeffff558bec8b4508
timestamp: 2018-05-08 22:49:05

Version Info:

CompanyName: Google Inc.
FileDescription: Google Update
FileVersion: 1.3.33.17
InternalName: Google Update
LegalCopyright: Copyright 2007-2010 Google Inc.
OriginalFilename: goopdate.dll
ProductName: Google Update
ProductVersion: 1.3.33.17
Translation: 0x0409 0x04b0

Strictor.260337 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.260337
FireEyeGeneric.mg.48ecdfa5e10802fa
McAfeeArtemis!48ECDFA5E108
CylanceUnsafe
BitDefenderGen:Variant.Strictor.260337
Cybereasonmalicious.5e1080
CyrenW32/Agent.CSK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ENTI
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Mokes.vho
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazr1bdqkwcaRQdzVjzboXI18)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Strictor.260337 (B)
AviraTR/ATRAPS.Gen
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Backdoor.Win32.Mokes.vho
GDataGen:Variant.Strictor.260337
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.R374759
BitDefenderThetaGen:NN.ZexaF.34182.ly0@aKHavXdi
ALYacGen:Variant.Strictor.260337
MalwarebytesTrojan.SmokeLoader.Generic
PandaTrj/Genetic.gen
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.ACGU!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Strictor.260337?

Strictor.260337 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment