Malware

Strictor.280664 malicious file

Malware Removal

The Strictor.280664 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.280664 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Strictor.280664?


File Info:

name: 80F66414228106F7DE52.mlw
path: /opt/CAPEv2/storage/binaries/3e63fc165e35d805afeded6699e9bad2aa26ee80f6b7c08128eae070e72d7718
crc32: ABE05B8C
md5: 80f66414228106f7de5204f7374329ee
sha1: 79140aab8d3405bf34347bf0864674dde0c31ab2
sha256: 3e63fc165e35d805afeded6699e9bad2aa26ee80f6b7c08128eae070e72d7718
sha512: 4b52c226fc862aa5072b840c8af0d2f71c66322f1fae0b88bc7af545205dfa7746ca0d24ee5f1a6b6385d138dfcccbce44d90857926b262ed28229c797d8da90
ssdeep: 49152:oKO/2KI5fiP+hzCjVR5b12Ncl/3iHSSHZawWQiY89ajbzSy:oKk2XI+wxYcl/3cSSH8fQi3a3uy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1788501FDB9559441C2C002750B6AFD706310AE4D3914ACDAA9E2BF8B3BFD38A75B1712
sha3_384: e655b20294020c73792d87ccc78135c8b7ee384b7f9708294c8f11b64a47d4b922f18041720ae12bf8f51d121007aa43
ep_bytes: 60be00c05b008dbe0050e4ff5783cdff
timestamp: 2013-02-27 08:22:37

Version Info:

CompanyName: www.GameModding.net
FileDescription: ModInstall 3.0
FileVersion: 3.0.0.4
InternalName:
LegalCopyright: www.GameModding.net
LegalTrademarks:
OriginalFilename:
ProductName: ModInstall
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0419 0x04e3

Strictor.280664 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.GameModding.3!c
MicroWorld-eScanGen:Variant.Strictor.280664
FireEyeGen:Variant.Strictor.280664
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!80F664142281
SangforTrojan.Win32.Gamemodding.Vi5c
K7AntiVirusAdware ( 004b90571 )
K7GWAdware ( 004b90571 )
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GameModding.A potentially unwanted
CynetMalicious (score: 100)
KasperskyUDS:HackTool.Win32.GameModding.gen
BitDefenderGen:Variant.Strictor.280664
AvastWin32:BackdoorX-gen [Trj]
EmsisoftGen:Variant.Strictor.280664 (B)
VIPREGen:Variant.Strictor.280664
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Strictor.280664
GoogleDetected
Antiy-AVLGrayWare/Win32.GameModding
ArcabitTrojan.Strictor.D44858
ZoneAlarmVHO:HackTool.Win32.GameModding.gen
VaristW32/GameModding.H.gen!Eldorado
ALYacGen:Variant.Strictor.280664
MAXmalware (ai score=82)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CGG23
RisingAdware.GameModding!8.131E0 (CLOUD)
YandexTrojan.GenAsa!wzHpzGYvhiM
IkarusPUA.GameModding
MaxSecureAdware.GameModding.a
FortinetRiskware/GameModding
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Strictor.280664?

Strictor.280664 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment