Worm

Worm:Win32/Soltern!pz (file analysis)

Malware Removal

The Worm:Win32/Soltern!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Soltern!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Soltern!pz?


File Info:

name: 7CB70661B6B29692DD94.mlw
path: /opt/CAPEv2/storage/binaries/a1eb91d15e7faa288e64ee2bac17cc353a1b608f1ac8dc3876a0e2443c82e02b
crc32: A4F4E6B6
md5: 7cb70661b6b29692dd943da3b396ee80
sha1: 69e239b6d944aee7df1878cc7334c08700d0fac3
sha256: a1eb91d15e7faa288e64ee2bac17cc353a1b608f1ac8dc3876a0e2443c82e02b
sha512: f10702a4145d650b8973e68e085de3d6360cce330c2c2ca01c18cc3d1c2d656fc87ebeaf3a5d4929680b97b91044afc5ae8b0b40806d2e0bf7664c63d8b9e8eb
ssdeep: 768:fllPp7JeTe5MLjH4B5NCPd7m+Z7hE6XmP0pD1j:flEK5SYB5s1Zm6XXP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12403F191297347A9C8E56FF1AD15CA4D40A8B8B049EC8B03E62765116EF4B7C8DF9C12
sha3_384: 08724d11542936a5393a2464db9b4c860f4fcbb20498c6061721ffd3cb1a25ef4b2b43bbe57eb616ab46b2059a77f130
ep_bytes: 60be002041008dbe00f0feff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Soltern!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.P2P-Worm.cmHfau!Mfvh
CAT-QuickHealW32.Desfiro.MUE.A8
SkyhighBehavesLike.Win32.Sytro.nc
McAfeeW32/Sytro.worm.gen!p2p
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.cmHfau!Mfvh
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00540e8a1 )
K7GWTrojan ( 00540e8a1 )
Cybereasonmalicious.6d944a
ArcabitTrojan.P2P-Worm.cmHfau!Mfvh
BaiduWin32.Trojan.Agent.aaw
VirITWorm.Win32.Soltern.AC
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Soltern.N
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Sytro-6840421-0
KasperskyP2P-Worm.Win32.Sytro.l
BitDefenderGen:Trojan.P2P-Worm.cmHfau!Mfvh
NANO-AntivirusTrojan.Win32.Sytro.fybz
AvastWin32:Sytro-AD [Wrm]
TencentP2P-Worm.Win32.Sytro.zb
EmsisoftGen:Trojan.P2P-Worm.cmHfau!Mfvh (B)
F-SecureWorm.WORM/Systro.I
DrWebWin32.HLLW.Sytro.31
ZillyaWorm.Sytro.Win32.22
TrendMicroWORM_SYTRO.L
SophosW32/Systro-L
IkarusVirus.Win32.Sytro
JiangminWorm/P2P.Sytro.l
VaristW32/Sytro.KUUM-5074
AviraWORM/Systro.I
Antiy-AVLWorm[P2P]/Win32.Sytro
Kingsoftmalware.kb.b.883
XcitiumWorm.Win32.Soltern.N@3uzl
MicrosoftWorm:Win32/Soltern!pz
ViRobotWorm.Win32.P2P-Sytro.32768
ZoneAlarmP2P-Worm.Win32.Sytro.l
GDataWin32.Trojan.PSE.12KRXTR
GoogleDetected
AhnLab-V3Worm/Win32.Sytro.C314843
Acronissuspicious
BitDefenderThetaAI:Packer.0036B3E021
TACHYONWorm/W32.DP-Sytro.Zen
VBA32BScope.TrojanDropper.Delf
Cylanceunsafe
TrendMicro-HouseCallWORM_SYTRO.L
RisingWorm.P2p.Sytro.l (CLASSIC)
YandexWorm.P2P.Sytro!tkeFifGfINo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.E867!tr
AVGWin32:Sytro-AD [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Soltern!pz?

Worm:Win32/Soltern!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment