Worm

P2P-Worm.Win32.Sytro.o removal instruction

Malware Removal

The P2P-Worm.Win32.Sytro.o is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What P2P-Worm.Win32.Sytro.o virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine P2P-Worm.Win32.Sytro.o?


File Info:

name: 709D80F1DCA8A75F6FF5.mlw
path: /opt/CAPEv2/storage/binaries/82de0670d66ef2307e5fe27cdb70b2ba9ee23012a975c8c9173cc205a5f37374
crc32: 56ACC73F
md5: 709d80f1dca8a75f6ff530a463b50df7
sha1: 803d688265b3da49ce9d8de13b698fda4f7c0e6d
sha256: 82de0670d66ef2307e5fe27cdb70b2ba9ee23012a975c8c9173cc205a5f37374
sha512: 1fad68e00aa6bf536b7c112ba0c3f2c099fa8222e4806f2427095822a69d94fcf3332215c96af4919292dcceef94319ee3ae6ceb6d75751ada9ccff1bc3cc59b
ssdeep: 3072:/xTqpdA3f6QNf2IPO4DpmWpAsfYbTOBoefYi6a9k20tAvpbkI8MuSsA4IYs+S7l:p2pdqfv2IPOGfXf5ovWv5qMu9ds+ul
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F049D63F1C058F3D0665A7DCD169068D0EBBE903D6E18566BE88A498F7B3D1B80D2D3
sha3_384: daab0c8b767a8ff0df03e077ab35919916fa011b7c17f2fcec2609cbea1de93d0ea699e152062603cbee1176bc5e39fa
ep_bytes: 558bec83c4f0b8acaf4100e878bafeff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

P2P-Worm.Win32.Sytro.o also known as:

BkavW32.FamVT.Sytro.Worm
LionicWorm.Win32.Sytro.lgBr
MicroWorld-eScanGen:Trojan.P2P-Worm.kKZ@aO2eyld
CAT-QuickHealWorm.SolternPMF.S30218104
SkyhighBehavesLike.Win32.Sytro.ch
McAfeeW32/Sytro.worm.gen!p2p
MalwarebytesSoltern.Worm.Spreader.DDS
VIPREGen:Trojan.P2P-Worm.kKZ@aO2eyld
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0048ed981 )
AlibabaWorm:Win32/Soltern.9caf
K7GWTrojan ( 0048ed981 )
Cybereasonmalicious.265b3d
ArcabitTrojan.P2P-Worm.E5548B
BitDefenderThetaAI:Packer.642A107921
VirITWorm.Win32.Sytro.O
SymantecW32.HLLW.Electron
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Soltern.NAA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Sytro-7108652-0
KasperskyP2P-Worm.Win32.Sytro.o
BitDefenderGen:Trojan.P2P-Worm.kKZ@aO2eyld
NANO-AntivirusTrojan.Win32.Sytro.eakbir
AvastWin32:Delf-UDU [Trj]
TencentWorm.Win32.Sytro.b
EmsisoftGen:Trojan.P2P-Worm.kKZ@aO2eyld (B)
BaiduWin32.Trojan.Agent.aaw
F-SecureWorm.WORM/Soltern.oald
DrWebWin32.HLLW.Sytro
ZillyaWorm.Sytro.Win32.14
TrendMicroWORM_SYTRO.O
SophosW32/Systro-O
IkarusWorm.Win32.Soltern
JiangminWorm/P2P.Sytro.o
VaristW32/Soltern.C.gen!Eldorado
AviraWORM/Soltern.oald
Antiy-AVLWorm[P2P]/Win32.Sytro.o
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Soltern.jet@5a5fyj
MicrosoftWorm:Win32/Soltern.AC
ZoneAlarmP2P-Worm.Win32.Sytro.o
GDataWin32.Worm.Soltern.A
GoogleDetected
AhnLab-V3Worm/Win.Sytro.R553225
Acronissuspicious
ALYacGen:Trojan.P2P-Worm.kKZ@aO2eyld
TACHYONWorm/W32.DP-Sytro.Zen
VBA32Worm.Sytro
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SYTRO.O
RisingWorm.Soltern!1.A328 (CLASSIC)
YandexTrojan.GenAsa!ahxhtFqwVFY
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Sytro.k
FortinetW32/Delf.E867!tr
AVGWin32:Delf-UDU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove P2P-Worm.Win32.Sytro.o?

P2P-Worm.Win32.Sytro.o removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment