Malware

Symmi.160 removal tips

Malware Removal

The Symmi.160 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.160 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Symmi.160?


File Info:

name: 02B15F8336E4E2C96A97.mlw
path: /opt/CAPEv2/storage/binaries/0955352eedf176aa3f44bccc5c1a1844517ef3d398ba3816f496d17be2f994e2
crc32: F33B40FA
md5: 02b15f8336e4e2c96a97995086639107
sha1: 3def50cec3fe1c030cf43e27652d122783441a63
sha256: 0955352eedf176aa3f44bccc5c1a1844517ef3d398ba3816f496d17be2f994e2
sha512: 98a68d450522db9496c077e093fdf79c9ae9cac2a8d53f2f62faa53c4c5810363dc71340e9d9c44df392171008292443adf2be9158e1f07680500016f07ebf2f
ssdeep: 3072:za2LtRrDBg8CFtCRlxHpSBDfibeMIEH6JEInIUtTBzMxUoJqMVoaBY9Vk:u2JlBgbkNkbceYH6JnIUtTBzuUoJqSlg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF040245D8125C23C8A2A2FED15BEAF241524DD0D2C59FA339DC7DCFF87A282B56520E
sha3_384: 190925008344ee92422fe2872b702442edfd1808b7144b70f9868607bf2ae39c252283a559e4b30b24e70eda5f76a370
ep_bytes: 6a6068c0324000e84e02000033db538b
timestamp: 2012-07-30 03:43:12

Version Info:

0: [No Data]

Symmi.160 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.160
FireEyeGeneric.mg.02b15f8336e4e2c9
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeePWS-Zbot.gen.sd
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.71671
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 003c45fc1 )
AlibabaTrojanSpy:Win32/Kuluoz.9c7bc607
K7GWSpyware ( 003c45fc1 )
Cybereasonmalicious.336e4e
BitDefenderThetaGen:NN.ZexaF.34212.lqW@ayNAdski
VirITTrojan.Win32.Generic.EUD
CyrenW32/Zbot.FV.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.AAO
TrendMicro-HouseCallTSPY_SYMMI_BK083787.TOMC
ClamAVWin.Spyware.Zbot-67583
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.160
NANO-AntivirusTrojan.Win32.Zbot.dxihye
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Citadel-T [Trj]
TencentMalware.Win32.Gencirc.10b654a2
Ad-AwareGen:Variant.Symmi.160
TACHYONTrojan-Spy/W32.ZBot.180224.AT
SophosMal/Generic-R + Mal/Kuluoz-A
ComodoTrojWare.Win32.Zbot.RUA@4x90nk
DrWebTrojan.PWS.Panda.2342
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_SYMMI_BK083787.TOMC
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
EmsisoftGen:Variant.Symmi.160 (B)
APEXMalicious
JiangminTrojanSpy.Zbot.bvwd
WebrootW32.Bot.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.573CB
KingsoftWin32.Troj.Zbot.(kcloud)
MicrosoftPWS:Win32/Zbot
ViRobotTrojan.Win32.A.Zbot.180224.FE
GDataGen:Variant.Symmi.160
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.C162887
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Symmi.160
MAXmalware (ai score=100)
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!vVtH6wtiBXo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.WEF!tr
AVGWin32:Citadel-T [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.160?

Symmi.160 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment