Trojan

Trojan:Win64/Solorigate.SB!dha (file analysis)

Malware Removal

The Trojan:Win64/Solorigate.SB!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Solorigate.SB!dha virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Trojan:Win64/Solorigate.SB!dha?


File Info:

crc32: CF915AED
md5: 0d7a178a0c0a7d2f2cc63e16dad95b45
name: 0D7A178A0C0A7D2F2CC63E16DAD95B45.mlw
sha1: df98c2dc09cd881c440171abbfc016bbd2924dbf
sha256: be9dbbec6937dfe0a652c0603d4972ba354e83c06b8397d6555fd1847da36725
sha512: 85bf430ac4218bcf1401ff7457239b082f0c306f0792c09ebb79da69ef0a118722e9e93609280de8bdf45260e6686b15b50e1bc5dc6ddbf43773284fff5445f2
ssdeep: 6144:hLE/TyirUcFowwhMFLedBltBVQa/MlXHW5jgtoDSz7h+ls:KTywUC3whMFoBlvf/MN22t29s
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
InternalName: 7z
FileVersion: 19.00
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 19.00
FileDescription: 7z Plugin
OriginalFilename: 7z.dll
Translation: 0x0409 0x04b0

Trojan:Win64/Solorigate.SB!dha also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Siggen2.3406
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Win64
ALYacTrojan.Agent.Raindrop
CylanceUnsafe
ZillyaTrojan.Raindrop.Win64.1
SangforTrojan.Win64.Solorigate.IOC
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win64/Raindrop.e0a0e426
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW64/Trojan.NLXQ-4745
ESET-NOD32Win64/Raindrop.A
APEXMalicious
AvastWin32:RainDrop-A [Trj]
ClamAVWin.Trojan.Raindrop-9835773-0
KasperskyTrojan.Win64.Raindrop.b
BitDefenderDeepScan:Generic.Raindrop.1.2126E827
ViRobotTrojan.Win64.S.Agent.347136
MicroWorld-eScanDeepScan:Generic.Raindrop.1.2126E827
TencentWin64.Trojan.Raindrop.Hpi
Ad-AwareDeepScan:Generic.Raindrop.1.2126E827
SophosMal/Generic-S
F-SecureTrojan:W64/RainDrop.A
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win64.RAINDROP.THBOHBA
McAfee-GW-EditionTrojan-Raindrop
FireEyeDeepScan:Generic.Raindrop.1.2126E827
EmsisoftDeepScan:Generic.Raindrop.1.2126E827 (B)
WebrootW32.Trojan.Raindrop
AviraTR/Redcap.hieyb
MicrosoftTrojan:Win64/Solorigate.SB!dha
ArcabitDeepScan:Generic.Raindrop.1.2126E827
AegisLabTrojan.Win64.Raindrop.4!c
ZoneAlarmTrojan.Win64.Raindrop.b
GDataDeepScan:Generic.Raindrop.1.2126E827
AhnLab-V3Malware/Win64.Generic.C4328222
McAfeeTrojan-Raindrop
MAXmalware (ai score=100)
VBA32Trojan.Win64.Raindrop
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win64.RAINDROP.THBOHBA
RisingTrojan.Raindrop!8.12414 (CLOUD)
YandexTrojan.Raindrop!pp4LdwDxw70
IkarusTrojan.Win64.Solorigate
MaxSecureTrojan.Malware.114188391.susgen
FortinetW64/Raindrop.B!tr
AVGWin32:RainDrop-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win64/Backdoor.Solorigate.HggASOoA

How to remove Trojan:Win64/Solorigate.SB!dha?

Trojan:Win64/Solorigate.SB!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment