Worm

Worm:Win32/Soltern!pz removal

Malware Removal

The Worm:Win32/Soltern!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Soltern!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Soltern!pz?


File Info:

name: FE767D15D853C4EEAFBD.mlw
path: /opt/CAPEv2/storage/binaries/9d44ac0c8477d7ab4098b53cb97c08e5f15f50368822a21dfbb48f4a0f72951b
crc32: D948A1B1
md5: fe767d15d853c4eeafbdb5423acfbb29
sha1: b97f8eeedc3577c77c473dc085b651ebebc78a84
sha256: 9d44ac0c8477d7ab4098b53cb97c08e5f15f50368822a21dfbb48f4a0f72951b
sha512: 20520e4573335b4ce0c5de9681ea13205d7129d1c18c78627b00331fc19c6514ee02ae6734101a54178a6bc084629e3a99eb9d5d3f5644d0f124b816c38cdf2f
ssdeep: 768:fllPp7JeTe5MLjH4B5NCPd7m+Z7hE6XmPkHledFCVzN7fpNWtBqt:flEK5SYB5s1Zm6X1Fe4PKkt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F013F10619768B89C5E45BB0DE25564482956CF204F88B13DFB74520EDF8B3CCEB8E76
sha3_384: 298eda346ce1bf996d16dbf380f2b40bbc2f943f4d0790fd70278b255fbcc7d558bb51063aef10b98e3149f120614e35
ep_bytes: 60be002041008dbe00f0feff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Soltern!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.P2P-Worm.cmIfau!Mfvh
ClamAVWin.Worm.Sytro-6840421-0
FireEyeGeneric.mg.fe767d15d853c4ee
CAT-QuickHealW32.Desfiro.MUE.A8
SkyhighBehavesLike.Win32.Sytro.pc
McAfeeW32/Sytro.worm.gen!p2p
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.cmIfau!Mfvh
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00540e8a1 )
K7GWTrojan ( 00540e8a1 )
Cybereasonmalicious.edc357
ArcabitTrojan.P2P-Worm.cmIfau!Mfvh
BitDefenderThetaAI:Packer.C1B86C2021
VirITWorm.Win32.Soltern.AC
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Soltern.N
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Sytro.l
BitDefenderGen:Trojan.P2P-Worm.cmIfau!Mfvh
NANO-AntivirusTrojan.Win32.Sytro.fybz
AvastWin32:Sytro-AD [Wrm]
TencentP2P-Worm.Win32.Sytro.zb
TACHYONWorm/W32.DP-Sytro.Zen
SophosW32/Systro-L
BaiduWin32.Trojan.Agent.aaw
F-SecureWorm.WORM/Systro.I
DrWebWin32.HLLW.Sytro.31
ZillyaWorm.Sytro.Win32.22
TrendMicroWORM_SYTRO.L
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.P2P-Worm.cmIfau!Mfvh (B)
IkarusVirus.Win32.Sytro
JiangminWorm/P2P.Sytro.l
GoogleDetected
AviraWORM/Systro.I
Antiy-AVLWorm[P2P]/Win32.Sytro
Kingsoftmalware.kb.b.787
XcitiumWorm.Win32.Soltern.N@3uzl
MicrosoftWorm:Win32/Soltern!pz
ViRobotWorm.Win32.P2P-Sytro.32768
ZoneAlarmP2P-Worm.Win32.Sytro.l
GDataWin32.Trojan.PSE.14IXRBR
VaristW32/Sytro.KUUM-5074
AhnLab-V3Worm/Win32.Sytro.C314843
Acronissuspicious
VBA32BScope.TrojanDropper.Delf
ALYacGen:Trojan.P2P-Worm.cmIfau!Mfvh
MAXmalware (ai score=81)
Cylanceunsafe
TrendMicro-HouseCallWORM_SYTRO.L
RisingWorm.P2p.Sytro.l (CLASSIC)
YandexWorm.P2P.Sytro!tkeFifGfINo
SentinelOneStatic AI – Malicious PE
FortinetW32/Delf.E867!tr
AVGWin32:Sytro-AD [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Soltern!pz?

Worm:Win32/Soltern!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment