Malware

What is “Symmi.16120 (B)”?

Malware Removal

The Symmi.16120 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.16120 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Nepali (India)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Symmi.16120 (B)?


File Info:

name: 857C1E83AB0FB249610E.mlw
path: /opt/CAPEv2/storage/binaries/0f117cdadb2c3b849a4054ad509b3ac4c29e732b6f78de231c26f2e40d3f5ca0
crc32: 2CE11526
md5: 857c1e83ab0fb249610ea268459a80ff
sha1: 270ef8cd0a4ca95971f05def13cb354dfce525ab
sha256: 0f117cdadb2c3b849a4054ad509b3ac4c29e732b6f78de231c26f2e40d3f5ca0
sha512: dc0f4d7de5b41fd1aea70f60db85e31088f6536e7aedc6d71f7d0584f89f2cbcaddd546f09120fb5c376aec9be7520ebb9dcc1db372367ad0f55c2461bb6ba5a
ssdeep: 3072:l9GAiXP90JuGEnvBkFAHplTOoX56B4uE7U4iy+LwldhzNkYMvMZqvRK56toRG9DO:w9yuPnvBtxYJxwphkYMvMZIDO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119841C6F7A3C4490C85421F295EAF39D3E6E7C664AD301622730F319EFE6E451A2DA07
sha3_384: fc1ee45d49e242d5e97a2db2ef58b68c93ce2d14459112bfe3542110589980529b3760b7117a3939e93f9189a02855c4
ep_bytes: 68c0134000e8eeffffff000000000000
timestamp: 2012-05-15 21:19:25

Version Info:

Translation: 0x0409 0x04b0
ProductName: dzmnnricis
FileVersion: 8.02.0003
ProductVersion: 8.02.0003
InternalName: smvhmtmcnhpjzk
OriginalFilename: smvhmtmcnhpjzk.exe

Symmi.16120 (B) also known as:

LionicTrojan.Win32.Vobfus.lCEI
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.16120
FireEyeGeneric.mg.857c1e83ab0fb249
CAT-QuickHealTrojan.VobfusMF.S21115995
McAfeeVBObfus.dv
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Symmi.16120
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.28c0
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.3ab0fb
BaiduWin32.Worm.VB.be
VirITTrojan.Win32.VbCrypt.DD
CyrenW32/Vobfus.AR.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AVW
APEXMalicious
ClamAVWin.Malware.Vobfus-9972871-0
KasperskyTrojan.Win32.Vobfus.igr
BitDefenderGen:Variant.Symmi.16120
NANO-AntivirusTrojan.Win32.Vobfus.jupbxe
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Pronny-K [Trj]
TencentTrojan.Win32.Koobface.l
TACHYONTrojan/W32.Vobfus.372736
SophosW32/AutoRun-BXE
F-SecureTrojan.TR/Barys.2490.jh.1
DrWebTrojan.VbCrypt.81
ZillyaTrojan.Vobfus.Win32.627940
TrendMicroWORM_VOBFUS.SM00
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.16120 (B)
IkarusTrojan.Barys
GDataWin32.Trojan.PSE1.7Y891Q
JiangminTrojan/Vobfus.mvh
GoogleDetected
AviraTR/Barys.2490.jh.1
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Autorun.AVW@4ual9c
ArcabitTrojan.Symmi.D3EF8
ViRobotTrojan.Win32.Vobfus.372736
ZoneAlarmTrojan.Win32.Vobfus.igr
MicrosoftWorm:Win32/Vobfus.FC
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R25085
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36250.wm0@aalxJ6gO
ALYacGen:Variant.Symmi.16120
MAXmalware (ai score=85)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.AutoRun!1.E3CB (CLASSIC)
YandexTrojan.GenAsa!BTV1Jeu2/jQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:Pronny-K [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.16120 (B)?

Symmi.16120 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment