Malware

Symmi.3505 removal

Malware Removal

The Symmi.3505 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.3505 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Symmi.3505?


File Info:

name: 755DC1F03691CE94E917.mlw
path: /opt/CAPEv2/storage/binaries/5356a950717eea9b8179e52ce70e9593de3df18254191c55f594064679210991
crc32: D19A9CC2
md5: 755dc1f03691ce94e9179938ec0abb00
sha1: 19d015272cba66727a65bad82ef447008f59efdc
sha256: 5356a950717eea9b8179e52ce70e9593de3df18254191c55f594064679210991
sha512: b266a6652ff0c009d88d4573be7bc306ad16bb369caf300771e4f7c1c5a4e227432b0d15c0d1799e4894067a1a65b702ceedff822c18385b9881d4f1bee38483
ssdeep: 3072:o9W8A/woNRgBN/buki1dQmo83ZNbQapxaO8BIA84+hcpz6GoFt:OWrx8BNKkuJXQIxTpYz6zt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136E312A52C41663ADA5F823D87AD0FCBDB6CE6520721DC47E3E43AEC69116683E11263
sha3_384: 5a852737bf7d2ee8dcbc30c55c003977d19b7e1b76a5a52c68edd16854b221b8cc72ede45b3de821f5900003d81d3b06
ep_bytes: 558bec6aff68b04a420068506a400064
timestamp: 2006-02-11 18:16:58

Version Info:

0: [No Data]

Symmi.3505 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.3505
FireEyeGeneric.mg.755dc1f03691ce94
McAfeePWS-Zbot.gen.aon
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Zbot.Win32.77958
SangforTrojan.Win32.Kryptik.AMMQ
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaTrojanPSW:Win32/Kryptik.8e38a40d
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.03691c
ArcabitTrojan.Symmi.DDB1
BitDefenderThetaAI:Packer.480F51051E
VirITTrojan.Win32.Panda.CWM
SymantecTrojan.Zbot!gen40
ESET-NOD32a variant of Win32/Kryptik.AMMQ
TrendMicro-HouseCallTSPY_SYMMI_BK083626.TOMC
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.3505
NANO-AntivirusTrojan.Win32.Zbot.bcbygb
APEXMalicious
TencentWin32.Trojan.Generic.Aglh
Ad-AwareGen:Variant.Symmi.3505
EmsisoftGen:Variant.Symmi.3505 (B)
ComodoMalware@#3n9ndd4dli3bb
DrWebTrojan.PWS.Panda.1936
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_SYMMI_BK083626.TOMC
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosML/PE-A + Mal/Generic-L
IkarusTrojan-PWS.Win32.Zbot
JiangminTrojanSpy.Zbot.cdcm
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
KingsoftWin32.Troj.Zbot.fd.(kcloud)
MicrosoftPWS:Win32/Zbot!CI
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.3505
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R39520
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Symmi.3505
TACHYONTrojan-Spy/W32.ZBot.152576.BN
CylanceUnsafe
AvastWin32:Kryptik-KBB [Trj]
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Kryptik!h+7ig1D9eVE
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Zbot.ASJ!tr
WebrootW32.Infostealer.Zeus
AVGWin32:Kryptik-KBB [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Symmi.3505?

Symmi.3505 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment