Worm

Worm:Win32/Soltern!pz malicious file

Malware Removal

The Worm:Win32/Soltern!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Soltern!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Soltern!pz?


File Info:

name: 45D5EB95FF927F3610D8.mlw
path: /opt/CAPEv2/storage/binaries/c415b7c8100fee46d7d177d9358594e76e9d41f408af3fa46506b5a24cd30984
crc32: 678F99B1
md5: 45d5eb95ff927f3610d8e82da4a0a3cd
sha1: df03c82a86f5649f6e732f4e91330166a543cc87
sha256: c415b7c8100fee46d7d177d9358594e76e9d41f408af3fa46506b5a24cd30984
sha512: af34ce760c1ad97b4817aff725cb3016082ecdc724924a5cd1118bafa2c8d68b6730469e37d329c87b4552be067e200ba4d1a470d02eeae6ad2f63159ebf910a
ssdeep: 6144:P08p9uIVlfV3p2Q1DyzdYwg92krimolrjzKgga5fD+tKXz7+GdQ6ee+LaP/pn0sb:F9TbflpFZpl76ee+LaP/9ToBKQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130E4D83EF4908F76C1CA377958DE0B50F7BA414E8B97275A02D8A1307DCA3981E7929D
sha3_384: a02120bbb7422f7cff9369bd5c030b5532c3d8498c928252ca107aa4b17f8c90687c14f773578f91f8d39cc23c83fd12
ep_bytes: 01000200de3100000703000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Soltern!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.412244
ClamAVWin.Worm.Soltern-1
SkyhighBehavesLike.Win32.Generic.jm
McAfeeArtemis!45D5EB95FF92
MalwarebytesSoltern.Worm.Spreader.DDS
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Variant.Ulise.412244
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.a86f56
ArcabitTrojan.Ulise.D64A54
BaiduWin32.Trojan.Agent.aaw
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AlibabaWorm:Win32/Soltern.8b975e2e
AvastWin32:Delf-UDU [Trj]
RisingWorm.Soltern!1.A328 (CLASSIC)
EmsisoftGen:Variant.Ulise.412244 (B)
F-SecureTrojan.TR/YAV.Minerva.suffc
VIPREGen:Variant.Ulise.412244
TrendMicroTROJ_GEN.R03BC0DAQ24
FireEyeGeneric.mg.45d5eb95ff927f36
SophosML/PE-A
IkarusTrojan.Win32.Krypt
GoogleDetected
AviraTR/YAV.Minerva.suffc
MAXmalware (ai score=88)
Antiy-AVLWorm[P2P]/Win32.Cosmu.a
GridinsoftTrojan.Win32.Gen.sa
MicrosoftWorm:Win32/Soltern!pz
GDataGen:Variant.Ulise.412244
VaristW32/Soltern.R.gen!Eldorado
AhnLab-V3Worm/Win.Soltern.R588690
ALYacGen:Variant.Ulise.412244
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAQ24
YandexTrojan.Agent!jN6s/KqjiUk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.219121203.susgen
FortinetW32/Soltern.C609!tr
BitDefenderThetaGen:NN.ZexaF.36680.PmZ@auqXpQp
AVGWin32:Delf-UDU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Soltern!pz?

Worm:Win32/Soltern!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment