PUA

What is “PUP.Optional.Solimba”?

Malware Removal

The PUP.Optional.Solimba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Solimba virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUP.Optional.Solimba?


File Info:

name: D50B47A987C003C4D7AA.mlw
path: /opt/CAPEv2/storage/binaries/7c30a4d4abb47aadf177cbc71ed176621170ca25ce3c81237cf90ea9940477fb
crc32: C4B76F27
md5: d50b47a987c003c4d7aa7101747a6f85
sha1: 13f1064287196b9ee2fd4252bb3959f7160225d4
sha256: 7c30a4d4abb47aadf177cbc71ed176621170ca25ce3c81237cf90ea9940477fb
sha512: ae3b917e55f1f2c6806e993419ef517e5ac24146c1a68a202c693ee08d169cdf2ba39092250f3304b86c1a0d86983635a3191605dcca647502f5b04c9de09cd9
ssdeep: 3072:6nOn7t7XpdpCCTg/sxFgJDil1iK6CQOslbEHEJuZ3Sg0CsJ5uIof2Kt9HlNyn:6KpdcCrTqDKDWSiCsehfxt9HKn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12104BF15EA63A8F2DD0B0570518BE77F6670BD2087189D07E3422A7BDCB35B29307B56
sha3_384: d3d76472653f9bbeaed26d362d9cfccbbafc0d5a43bf958bfbeb92c2b591b72b34ee7f65a8a72955fcb6ec63e273363c
ep_bytes: 5589e557565381ecac010000ff157483
timestamp: 2011-08-30 15:46:24

Version Info:

FileDescription: emule
FileVersion: 2.2.37.0
LegalCopyright: Copyright 2010
ProductName: emule
Translation: 0x0000 0x04e4

PUP.Optional.Solimba also known as:

LionicRiskware.Win32.Morstar.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Adware.Solimba.1
FireEyeGeneric.mg.d50b47a987c003c4
CAT-QuickHealPUA.Solimbaapl.Gen
McAfeeArtemis!D50B47A987C0
MalwarebytesPUP.Optional.Solimba
VIPREGen:Variant.Adware.Solimba.1
SangforPUA.Win32.Sign.a
K7AntiVirusUnwanted-Program ( 00586e111 )
AlibabaAdWare:MSIL/Solimba.6d92f349
K7GWUnwanted-Program ( 00586e111 )
CrowdStrikewin/grayware_confidence_100% (W)
BaiduWin32.Adware.Solimba.a
CyrenW32/Solimba.B.gen!Eldorado
SymantecPUA.Downloader
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Solimba.H potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.Morstar.gen
BitDefenderGen:Variant.Adware.Solimba.1
NANO-AntivirusRiskware.Win32.Solimba.dwzbbr
AvastMSIL:Solimba-J [PUP]
RisingAdware.Solimba/NSIS!1.D5F1 (CLASSIC)
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1353950
DrWebTrojan.Solimba.48
ZillyaAdware.4SharedCRT.Win32.888
McAfee-GW-EditionAdware-Fiseria
EmsisoftApplication.InstallCore (A)
SentinelOneStatic AI – Suspicious PE
GDataMSIL.Adware.Solimba.D
AviraHEUR/AGEN.1338404
Antiy-AVLGrayWare[AdWare]/MSIL.Solimba
XcitiumApplicUnwnt@#hyk7ibjt2a5b
ArcabitTrojan.Adware.Solimba.1
ViRobotAdware.Solimba.184424
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Morstar.gen
MicrosoftPUADlManager:Win32/Solimba
GoogleDetected
AhnLab-V3Trojan/Win32.Downloader.R38429
ALYacGen:Variant.Adware.Solimba.1
MAXmalware (ai score=86)
VBA32Trojan.Occamy
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SPNR.03GA14
IkarusPUA.MSIL.Solimba
MaxSecureVirus.W32.AdWare.Generic_229078
FortinetAdware/Solimba
AVGMSIL:Solimba-J [PUP]
DeepInstinctMALICIOUS

How to remove PUP.Optional.Solimba?

PUP.Optional.Solimba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment