Malware

Symmi.20325 (B) removal tips

Malware Removal

The Symmi.20325 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.20325 (B) virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Symmi.20325 (B)?


File Info:

crc32: CA210029
md5: 8b3427b8db88f0ca517774eb32025bb0
name: 8B3427B8DB88F0CA517774EB32025BB0.mlw
sha1: 04ae9dc9c6e713632aa7155cee7e61cf81a91921
sha256: 8b2018a8f328cac45126d16b9e41e80156a6e49f738bdafafe12c7865925cab6
sha512: 67216e447007b06666acca00d75d1cd085b57fadf5b1b50285ce78b9305fd2ca63ffd8c39b296a0c09bf16c295dbda83111fdbed3c5218ca3c34dacbe07f0352
ssdeep: 3072:/2fopKbc1wQLNUTcFMuiLpv9n4FBlo40:Aoz2QUEMugPn4F71
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2006-2012 - Soft-Zone International
InternalName: initwiz
FileVersion: 2.3.5.1
CompanyName: Soft-Zone International
ProductName: TPM Initialization Wizard
ProductVersion: 2.3.5.1
FileDescription: TPM Initialization Wizard
OriginalFilename: initwiz
Translation: 0x1009 0x04b0

Symmi.20325 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4091 )
DrWebTrojan.PWS.Panda.4026
CynetMalicious (score: 90)
ALYacGen:Variant.Symmi.20325
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.8889
SangforRansom.Win32.Urausy.C
AlibabaRansom:Win32/Foreign.4a536048
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.8db88f
CyrenW32/Ransom.UWCF-0643
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nbhu
BitDefenderGen:Variant.Symmi.20325
NANO-AntivirusTrojan.Win32.Panda.eccafp
MicroWorld-eScanGen:Variant.Symmi.20325
TencentWin32.Trojan.Foreign.Eawy
Ad-AwareGen:Variant.Symmi.20325
SophosMal/Generic-R + Mal/Ransom-AL
ComodoMalware@#gpj73bwrhjbe
BitDefenderThetaGen:NN.ZexaF.34628.gmKfau1@TVlk
VIPRETrojan.Win32.Reveton.b!ag (v)
TrendMicroTROJ_SPNR.07DP13
McAfee-GW-EditionRansom-FAXC!8B3427B8DB88
FireEyeGeneric.mg.8b3427b8db88f0ca
EmsisoftGen:Variant.Symmi.20325 (B)
JiangminTrojan.Foreign.aja
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1100700
eGambitGeneric.Malware
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftRansom:Win32/Urausy.E
ArcabitTrojan.Symmi.D4F65
AegisLabTrojan.Win32.Foreign.4!c
GDataGen:Variant.Symmi.20325
TACHYONRansom/W32.Foreign.151040
AhnLab-V3Trojan/Win32.Foreign.R65441
McAfeeRansom-FAXC!8B3427B8DB88
MAXmalware (ai score=100)
VBA32Hoax.Foreign
MalwarebytesMalware.Heuristic.1003
PandaTrj/Dtcontx.D
TrendMicro-HouseCallTROJ_SPNR.07DP13
RisingRansom.Foreign!8.292 (CLOUD)
YandexTrojan.GenAsa!4gBeo9K9Kbw
IkarusWin32.LockScreen
MaxSecureTrojan.Malware.5665941.susgen
FortinetW32/Zbot.AAO!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.Foreign.HgIASOgA

How to remove Symmi.20325 (B)?

Symmi.20325 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment