Malware

Symmi.16042 removal

Malware Removal

The Symmi.16042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.16042 virus can do?

  • At least one process apparently crashed during execution
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Symmi.16042?


File Info:

name: 7912B1327FD9F9C7CA3C.mlw
path: /opt/CAPEv2/storage/binaries/8485e100678a74dffcf44fb1bc798ccfe732d88b1cac9845e61c7ca0d065e9d3
crc32: 9AA76F78
md5: 7912b1327fd9f9c7ca3cbe4f4f3a21a9
sha1: 2872823ff561d8a800e86c4227ae204d7dc7a4b4
sha256: 8485e100678a74dffcf44fb1bc798ccfe732d88b1cac9845e61c7ca0d065e9d3
sha512: ba86f20d4c7674ea8924dd2932f7bf7cced8d67cc96f8b4f2218a948a63e267cbfc2caf2386210b9d07becb28ae74cf0dcde0315f9f6ddf40bedd804476995fc
ssdeep: 6144:LXC9CTIUTkKQQd1CS7O57KX7C2snVuukBlsz:LXCRUTkOESgmrynlSC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB44130E54134232FF090BF4B3D5D9C506556DAC33FBA85EE8667D2596F32870D22A4E
sha3_384: f1caf5584a708aa02e64d779a2f555342972c6a89c7bb34f36f05c87fbdd8784d30aa993c0932b476b64fd5863db3469
ep_bytes: 6a6068d8504000e8810d0000bf940000
timestamp: 2012-05-29 17:53:49

Version Info:

0: [No Data]

Symmi.16042 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.16042
FireEyeGeneric.mg.7912b1327fd9f9c7
CAT-QuickHealTrojanPWS.ZBot.S41924
McAfeePWS-Zbot.gen.bfo
CylanceUnsafe
ZillyaTrojan.Injector.Win32.117838
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f89351 )
AlibabaTrojan:Win32/Injector.40165948
K7GWTrojan ( 004f89351 )
Cybereasonmalicious.27fd9f
BitDefenderThetaGen:NN.ZexaF.34212.qqX@aCjOFohc
VirITTrojan.Win32.Generic.PSD
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Injector.SAZ
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-49489
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.16042
NANO-AntivirusTrojan.Win32.Panda.drezrh
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
APEXMalicious
TencentMalware.Win32.Gencirc.10c4b98f
Ad-AwareGen:Variant.Symmi.16042
EmsisoftGen:Variant.Symmi.16042 (B)
ComodoTrojWare.Win32.Kryptik.AAE@4qhzib
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PWS.Panda.2000
VIPRETrojan-PWS.Win32.Zbot.ad (v)
McAfee-GW-EditionBehavesLike.Win32.ZBot.dc
SophosMal/Generic-R + Troj/Zbot-DQS
IkarusTrojan.Win32.Menti
GDataGen:Variant.Symmi.16042
JiangminTrojan/Generic.adcna
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Symmi.D3EAA
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!dtc
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R28498
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Symmi.16042
TACHYONTrojan-Spy/W32.ZBot.272384.W
MalwarebytesGeneric.Malware/Suspicious
AvastWin32:Citadel [Trj]
RisingTrojan.Crypto!8.364 (CLOUD)
YandexTrojan.GenAsa!mxQf7INOpgY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.AFVU!tr
AVGWin32:Citadel [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Symmi.16042?

Symmi.16042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment