Malware

Strictor.285110 removal instruction

Malware Removal

The Strictor.285110 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.285110 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Strictor.285110?


File Info:

name: 0F8AD8DFE4E150265584.mlw
path: /opt/CAPEv2/storage/binaries/dfc2fe54ca4a3c870af841282b730ce4f8e88eef24aa0e04703971e073ff39bc
crc32: 24DE0CC9
md5: 0f8ad8dfe4e1502655848b6022fba5ef
sha1: eaa236c6cb80742ab63c853859a44912c6452334
sha256: dfc2fe54ca4a3c870af841282b730ce4f8e88eef24aa0e04703971e073ff39bc
sha512: a79f2e9635383937465b5cc273b6b1b4ea32e718d2cb0f93193cb8a282556112962db16a08d543e5ec2763a708dd877997ec4e77ca8a0076147cfa3d83ca1af9
ssdeep: 98304:lYmOdAeNFCUkyDRKzbFiO6HC83x02rCbOBFswq8KDyzNhoCdUlYKclU:lYmakSKzMRaJbBpyzN+C2g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17596BE02BD1ED0A8D9194178FD2246FD79A07E08FC604DABB2D4BF2EEC32B51D5265C9
sha3_384: 1527ee12cba24c281612dfc970c0502fb76e5bc7cf145ffe718eed1caab377cac2cb53b7eb35bd70ca68752dd334db83
ep_bytes: e95878ffffb1ad9d5d878abd9b4259c2
timestamp: 2013-03-09 07:36:29

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Strictor.285110 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Strictor.285110
FireEyeGeneric.mg.0f8ad8dfe4e15026
SkyhighBehavesLike.Win32.ToolEPLLib.rh
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Bulz.115627
SangforSuspicious.Win32.Save.ins
K7AntiVirusAdware ( 0058290e1 )
K7GWAdware ( 0058290e1 )
Cybereasonmalicious.6cb807
ArcabitTrojan.Bulz.D1C3AB
BitDefenderThetaGen:NN.ZexaF.36792.@F0@aORyKgcb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Strictor.285110
AvastWin32:Evo-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:L2sTTwOimXpTWDa88nFQLQ)
EmsisoftApplication.Generic (A)
Trapminemalicious.moderate.ml.score
SophosMal/VMProtBad-A
IkarusPUA.FlyStudio
WebrootTrojan.Dropper.Gen
VaristW32/OnlineGames.HG.gen!Eldorado
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.b.940
XcitiumTrojWare.Win32.Agent.ISVQ@5mbonp
GDataWin32.Trojan.Kryptik.HK@susp
GoogleDetected
VBA32BScope.Trojan.BtcMine
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Strictor.285110?

Strictor.285110 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment