Worm

What is “Worm:Win32/Soltern!pz”?

Malware Removal

The Worm:Win32/Soltern!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Soltern!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Soltern!pz?


File Info:

name: 725485497B8481BCA874.mlw
path: /opt/CAPEv2/storage/binaries/d6d65fc4479984bfde67b5a24c946da286ac6e0bf3b1fc9d522606026cb3d47c
crc32: C5D64A89
md5: 725485497b8481bca8745c0c3b020ba0
sha1: 837e7d26a7c314735dc669569763d636a9ac8478
sha256: d6d65fc4479984bfde67b5a24c946da286ac6e0bf3b1fc9d522606026cb3d47c
sha512: 5faba8e368c7d387213a3addbe38609ed98d5f9e51f3706cb8788c84b6e8b6a47b77fd9312a9946a5cb9b3390c2de7182d71edbe2eafd7336c95671e024704fb
ssdeep: 768:fllPp7JeTe5MLjH4B5NCPd7m+Z7hE6XmPA+Z6Px:flEK5SYB5s1Zm6Xn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16603F142282687A9C9ED3FB09E064A4CA1E958B04AFDC313DA665001FFF463C99B1D72
sha3_384: c2c7287b88555365ccffd5987703c63b569db7b1a2698974fa315d7db507250b246e87708273e43c84a3d10251a1b24f
ep_bytes: 60be002041008dbe00f0feff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Soltern!pz also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Sytro.31
MicroWorld-eScanGen:Trojan.P2P-Worm.cmIfau!Mfvh
CAT-QuickHealW32.Desfiro.MUE.A8
SkyhighBehavesLike.Win32.Sytro.pc
McAfeeW32/Sytro.worm.gen!p2p
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.cmIfau!Mfvh
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00540e8a1 )
K7GWTrojan ( 00540e8a1 )
Cybereasonmalicious.6a7c31
ArcabitTrojan.P2P-Worm.cmIfau!Mfvh
BitDefenderThetaAI:Packer.C1B86C2021
VirITWorm.Win32.Soltern.AC
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Soltern.N
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Sytro-6840421-0
KasperskyP2P-Worm.Win32.Sytro.l
BitDefenderGen:Trojan.P2P-Worm.cmIfau!Mfvh
NANO-AntivirusTrojan.Win32.Sytro.fybz
TencentP2P-Worm.Win32.Sytro.zb
EmsisoftGen:Trojan.P2P-Worm.cmIfau!Mfvh (B)
F-SecureWorm.WORM/Systro.I
BaiduWin32.Trojan.Agent.aaw
ZillyaWorm.Sytro.Win32.22
TrendMicroWORM_SYTRO.L
SophosW32/Systro-L
IkarusVirus.Win32.Sytro
JiangminWorm/P2P.Sytro.l
VaristW32/Sytro.KUUM-5074
AviraWORM/Systro.I
Antiy-AVLWorm[P2P]/Win32.Sytro
XcitiumWorm.Win32.Soltern.N@3uzl
MicrosoftWorm:Win32/Soltern!pz
ViRobotWorm.Win32.P2P-Sytro.32768
ZoneAlarmP2P-Worm.Win32.Sytro.l
GDataWin32.Trojan.PSE.14IXRBR
GoogleDetected
AhnLab-V3Worm/Win32.Sytro.C314843
Acronissuspicious
VBA32BScope.TrojanDropper.Delf
TACHYONWorm/W32.DP-Sytro.Zen
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallWORM_SYTRO.L
RisingWorm.P2p.Sytro.l (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.E867!tr
AVGWin32:Sytro-AD [Wrm]
AvastWin32:Sytro-AD [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Soltern!pz?

Worm:Win32/Soltern!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment