Malware

Symmi.20325 removal tips

Malware Removal

The Symmi.20325 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.20325 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Symmi.20325?


File Info:

crc32: 87125E3E
md5: cbc9df2bd54482848ebfe0506798c2ce
name: CBC9DF2BD54482848EBFE0506798C2CE.mlw
sha1: 24f6cbc5202c6cb35d79d2ab9b1718bfe0ef1cea
sha256: 4e83144e37aab503dbf0f0ad83f910bc298ec773fd20c06d6f97808d304b8e1d
sha512: 1de7b9349c1afdfcf97c5dc95ead2363544ef0595db4ef692dfac84b5a50143664259de13b68607f54ea40106687aa1d198d7d38339bfefa789ef316f6f2279c
ssdeep: 6144:o67sNP93FAUJkoAyD5XBas2NZge0ZZlsTOIx4y04+cA:oR93yoA+XBL2XqZlsre
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2009-2012 - Bigasoft Group
InternalName: relogutil
FileVersion: 3.0.2.1
CompanyName: Bigasoft Group
ProductName: Performance Relogging Utility
ProductVersion: 3.0.2.1
FileDescription: Performance Relogging Utility
OriginalFilename: relogutil
Translation: 0x1009 0x04b0

Symmi.20325 also known as:

MicroWorld-eScanGen:Variant.Symmi.20325
ALYacGen:Variant.Symmi.20325
CylanceUnsafe
VIPRETrojan.Win32.Reveton.b!ag (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e39b1 )
BitDefenderGen:Variant.Symmi.20325
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.bd5448
BitDefenderThetaGen:NN.ZexaF.34590.pmKfaaQxkqaO
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:LockScreen-WV [Trj]
NANO-AntivirusTrojan.Win32.Panda.crbezn
Ad-AwareGen:Variant.Symmi.20325
EmsisoftGen:Variant.Symmi.20325 (B)
F-SecureHeuristic.HEUR/AGEN.1113290
DrWebTrojan.PWS.Panda.2401
ZillyaTrojan.Zbot.Win32.123689
TrendMicroTROJ_RANSOM.SMKJ
McAfee-GW-EditionPWS-Zbot-FAPI!0E6E7A70DEF9
SophosMal/Generic-S
IkarusTrojan-PWS.Win32.Zbot
JiangminTrojan/Generic.awlgh
AviraHEUR/AGEN.1113290
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Symmi.D4F65
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R65577
McAfeeArtemis!CBC9DF2BD544
VBA32TrojanSpy.Zbot
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32Win32/Spy.Zbot.AAO
TrendMicro-HouseCallTROJ_RANSOM.SMKJ
TencentWin32.Trojan.Generic.Tccf
YandexTrojan.GenAsa!Uiy13bsqUU8
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_61%
FortinetW32/Zbot.AAO!tr
AVGWin32:LockScreen-WV [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.767

How to remove Symmi.20325?

Symmi.20325 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment