Worm

Worm:Win32/Soltern!pz removal instruction

Malware Removal

The Worm:Win32/Soltern!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Soltern!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Soltern!pz?


File Info:

name: 9B00D78C7CB3505600F9.mlw
path: /opt/CAPEv2/storage/binaries/cba79029ca8caac6e268b147e53c047537da76b35f158c8481816ca6e3ae6e08
crc32: F09F3D76
md5: 9b00d78c7cb3505600f9476264908bda
sha1: e8160e9e351d4efd39c2344b4fc2aba6d4748401
sha256: cba79029ca8caac6e268b147e53c047537da76b35f158c8481816ca6e3ae6e08
sha512: bcfcee0407e7ffd30310abc52aaabbbd62bf1835a549efcf8c24633fd1d6989596887b7143bdd77bd6e16f863f6d3bb5e825aea314911097e8fb9e66e0973f02
ssdeep: 768:fllPp7JeTe5MLjH4B5NCPd7m+Z7hE6XmPkHledFCVzN7fpNWtBVQS:flEK5SYB5s1Zm6X1Fe4PK3QS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A13F10605228B99C5E55BB1DE19564885A0ACF105FDCB13DFAB8510EDF8B3CCEB8D63
sha3_384: d6cede10672c58f4376159ca730dce6290c42599997369ee4cf755080f2b9b9bdd4afabc7557f98ea0b4cd0eb49be760
ep_bytes: 60be002041008dbe00f0feff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Soltern!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.P2P-Worm.cmIfau!Mfvh
CAT-QuickHealW32.Desfiro.MUE.A8
SkyhighBehavesLike.Win32.Sytro.pc
McAfeeW32/Sytro.worm.gen!p2p
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.P2P-Worm.cmIfau!Mfvh
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00540e8a1 )
K7GWTrojan ( 00540e8a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.P2P-Worm.cmIfau!Mfvh
BaiduWin32.Trojan.Agent.aaw
VirITWorm.Win32.Soltern.AC
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Soltern.N
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Sytro-6840421-0
KasperskyP2P-Worm.Win32.Sytro.l
BitDefenderGen:Trojan.P2P-Worm.cmIfau!Mfvh
NANO-AntivirusTrojan.Win32.Sytro.fybz
AvastWin32:Sytro-AD [Wrm]
TencentP2P-Worm.Win32.Sytro.zb
EmsisoftGen:Trojan.P2P-Worm.cmIfau!Mfvh (B)
F-SecureWorm.WORM/Systro.I
DrWebWin32.HLLW.Sytro.31
ZillyaWorm.Sytro.Win32.22
TrendMicroWORM_SYTRO.L
SophosW32/Systro-L
IkarusVirus.Win32.Sytro
JiangminWorm/P2P.Sytro.l
VaristW32/Sytro.KUUM-5074
AviraWORM/Systro.I
Antiy-AVLWorm[P2P]/Win32.Sytro
XcitiumWorm.Win32.Soltern.N@3uzl
MicrosoftWorm:Win32/Soltern!pz
ViRobotWorm.Win32.P2P-Sytro.32768
ZoneAlarmP2P-Worm.Win32.Sytro.l
GDataWin32.Trojan.PSE.14IXRBR
GoogleDetected
AhnLab-V3Worm/Win32.Sytro.C314843
Acronissuspicious
VBA32BScope.TrojanDropper.Delf
TACHYONWorm/W32.DP-Sytro.Zen
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_SYTRO.L
RisingWorm.P2p.Sytro.l (CLASSIC)
YandexWorm.P2P.Sytro!tkeFifGfINo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.E867!tr
BitDefenderThetaAI:Packer.C1B86C2021
AVGWin32:Sytro-AD [Wrm]
Cybereasonmalicious.e351d4
DeepInstinctMALICIOUS

How to remove Worm:Win32/Soltern!pz?

Worm:Win32/Soltern!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment