Malware

Symmi.16110 malicious file

Malware Removal

The Symmi.16110 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.16110 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Symmi.16110?


File Info:

crc32: AC4A25BF
md5: c1fc538db54b73a62632c2647ae5ad54
name: C1FC538DB54B73A62632C2647AE5AD54.mlw
sha1: 3f99fc62d25b4926a8df16a22ed2d563783d61a8
sha256: 45bd17e0df6cb13adada935c80f643a5330f451e34ff3208d10cb39bd259fad8
sha512: 894a909940c2a7c9644486fc486737a622e5f3950421eba0472a4693698491bb6d46352d6b3b76eef49cf458b3d0f368d11328d0543d7e6637903ea5a53d9b4a
ssdeep: 6144:zT6VgLvW1HAzNPEaYqfyNJIwGMVYUx0h7LfLJFzawpVWbllJ2sTJiv19D1dS38EO:C1HAzpGN/vYp7jF2blsv1Q3+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: License: MPL 1.1/GPL 2.0/LGPL 2.1
InternalName: prism
FileVersion: 1.9.2pre
CompanyName: Mozilla Foundation
BuildID: 20100325230433
LegalTrademarks: Mozilla
Comments:
ProductName: Prism
ProductVersion: 1.9.2pre
FileDescription:
OriginalFilename: prism.exe
Translation: 0x0000 0x04b0

Symmi.16110 also known as:

K7AntiVirusSpyware ( 0055e3db1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.786
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.16110
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.5853
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.db54b7
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Blocker.avst
BitDefenderGen:Variant.Symmi.16110
NANO-AntivirusTrojan.Win32.Blocker.eftclh
MicroWorld-eScanGen:Variant.Symmi.16110
Ad-AwareGen:Variant.Symmi.16110
SophosML/PE-A
ComodoTrojWare.Win32.Agent.ADWN@51g8so
BitDefenderThetaGen:NN.ZevbaF.34738.Iq1@aG4Mc1dO
VIPREWorm.Win32.Phorpiex.ba (v)
McAfee-GW-EditionPWS-Zbot.gen.arw
FireEyeGeneric.mg.c1fc538db54b73a6
EmsisoftGen:Variant.Symmi.16110 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.pqe
AviraHEUR/AGEN.1124780
eGambitUnsafe.AI_Score_81%
Antiy-AVLTrojan/Generic.ASMalwS.136BBB
MicrosoftVirTool:Win32/Injector.gen!DL
ArcabitTrojan.Symmi.D3EEE
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Symmi.16110
AhnLab-V3Spyware/Win32.Zbot.R54243
McAfeePWS-Zbot.gen.arw
MAXmalware (ai score=100)
VBA32Hoax.Blocker
YandexTrojan.GenAsa!3KjxQYglcDs
IkarusTrojan-Ransom.Blocker
FortinetW32/Injector.FKNG!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Symmi.16110?

Symmi.16110 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment