Threat Database Trojans Trojan.Soltern.CA

Trojan.Soltern.CA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,329
Threat Level: 80 % (High)
Infected Computers: 1,943
First Seen: October 24, 2021
Last Seen: April 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Soltern.CA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it is essential to understand its nature and how to remove it effectively.

What Is Trojan.Soltern.CA?

Trojan.Soltern.CA is a type of Trojan horse malware, which is a malicious program that disguises itself as legitimate software. It is designed to gain unauthorized access to a computer system, allowing attackers to steal sensitive information, disrupt system operations, or use the infected computer for malicious activities. The name "Trojan.Soltern.CA" suggests that it is a specific variant of Trojan horse malware, but its exact characteristics and behavior may vary.

How Trojan.Soltern.CA Operates

Trojan.Soltern.CA, like other Trojan horses, typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can create backdoors, allowing remote access to the infected computer. It may also install additional malware, modify system settings, or steal sensitive information such as login credentials, credit card numbers, or personal data. The malware can communicate with its command and control servers to receive updates, transmit stolen data, or execute commands from its operators.

Symptoms of Infection

The symptoms of a Trojan.Soltern.CA infection can vary, but common signs include slow system performance, unexpected pop-ups, and unusual network activity. You may also notice that your computer is behaving erratically, such as crashing or freezing frequently. Additionally, you may receive alerts from your security software indicating that malicious activity has been detected. It is essential to be vigilant and monitor your system for any suspicious activity, as some Trojans can operate silently, making them difficult to detect.

How to Remove Trojan.Soltern.CA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all instances of the malware.
  3. Uninstall any suspicious programs that may be related to the Trojan.Soltern.CA infection. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This will help remove any malicious extensions or settings that may have been installed by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Soltern.CA requires a thorough and careful approach to ensure that all instances of the malware are eliminated. By following the steps outlined above, you can help protect your system and prevent further damage. It is also essential to practice good security habits, such as regularly updating your software, using strong passwords, and being cautious when opening email attachments or clicking on links. Remember that prevention is key, and staying informed about the latest threats and security best practices can help you stay safe online.

Analysis Report

General information

Family Name: Trojan.Soltern.CA
Signature status: No Signature

Known Samples

MD5: 08a54c5c3e5fbc74ee7eeb0b776bb399
SHA1: ee528ca9ed3066cade9a66ef073427a10b2d3bbf
SHA256: F85F47DD21F8B69D856022F3F86096A2B0F6668CFB0BFA12593C0AE75F0CCDF4
File Size: 704.00 KB, 704000 bytes
MD5: c1f65a13185059c351a66506f0733bfd
SHA1: 820e6e0bad10be9b1a8385762027f29cf023164b
SHA256: B770092EDCD253CACC638CE08A8FB3BC215E410DCA2B29E32F3BA07F4A0D01FB
File Size: 836.37 KB, 836373 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments http://enetwork.ncbuy.com
Company Name
  • kemira
  • NetCent Communications
File Description
  • HangARoo
  • pix & pax in: operation clearwater
File Version
  • 1.1
  • 1.0
Internal Name NCBuy Entertainment Network HangARoo
Legal Copyright
  • © Copyright 2001 NetCent Communications
  • © Copyright 2002 mediasquad
Original Filename
  • HangARoo.exe
  • kemira - operation clearwater.exe
Product Name
  • HangARoo
  • pix & pax in: operation clearwater
Product Version
  • 1.1
  • 1.0

File Traits

  • 2+ executable sections
  • big overlay
  • HighEntropy
  • x86

Block Information

Total Blocks: 514
Potentially Malicious Blocks: 16
Whitelisted Blocks: 498
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 x 0 0 x 0 1 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Soltern.CA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\hangaroo.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\jgl_rt\hangaroo_proj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\jgl_rt\jesterrun0.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\jgl_rt\jweb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Ufkgnxlv\AppData\Local\Temp\Jgl_Rt\hangaroo_proj.exe (NULL)

Trending

Most Viewed

Loading...