Malware

Symmi.45094 information

Malware Removal

The Symmi.45094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.45094 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Symmi.45094?


File Info:

name: 1DE0502F12DBDC550333.mlw
path: /opt/CAPEv2/storage/binaries/1fc773db1538c1c24108cbae7b2352fd82215f8e60567b927f36f644080d82ea
crc32: 2CA3BCA8
md5: 1de0502f12dbdc550333faafa6ae7971
sha1: e7c9d9c129d2be8f7dbbc59dc4a6290a4de392fe
sha256: 1fc773db1538c1c24108cbae7b2352fd82215f8e60567b927f36f644080d82ea
sha512: e1181394dd9aa69db73dcd5f771d094841b10d2e783576da64d1a33ad4fccc483e3a33433a9f57152f8d7289240974c2ae152c3f497a6129889bdd2a43a92e49
ssdeep: 1536:Kvdxa+rd9sJv4KFXC5plKnp08Li/70a2EJ+KxXQKYZhWXfaghqpRF5x8Xjy:K6Jv4KE54Li72Q+K9oZgXf6/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EED3AE1035D5C473D45282BB8856CB28576738A65B37ADCB2FC948E94F386E3E73A708
sha3_384: 5c700ff9c131edd4770fddd77040472f2628d917a5a93ec19d6f915e3a89ab94e7ba0ca0bc54d27bae13786b9bfe39f8
ep_bytes: e88d1d0000e916feffff3b0d18f74100
timestamp: 2011-10-03 03:38:45

Version Info:

0: [No Data]

Symmi.45094 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Kuluoz.4
MicroWorld-eScanGen:Variant.Symmi.45094
FireEyeGeneric.mg.1de0502f12dbdc55
CAT-QuickHealTrojanDownloader.Kuluoz.D5
ALYacGen:Variant.Symmi.45094
CylanceUnsafe
VIPREGen:Variant.Symmi.45094
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.f12dbd
BitDefenderThetaGen:NN.ZexaF.34606.imW@amnkbhli
VirITTrojan.Win32.Crypt3.AIDG
CyrenW32/A-1faaf2d1!Eldorado
SymantecPacked.Generic.456
ESET-NOD32a variant of Win32/Kryptik.CIBL
APEXMalicious
ClamAVWin.Trojan.NeutrinoPOS-6333858-3
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.45094
NANO-AntivirusTrojan.Win32.Aspxor.ddnzqd
SUPERAntiSpywareTrojan.Agent/Gen-Kuluoz
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c55b6
Ad-AwareGen:Variant.Symmi.45094
TACHYONWorm/W32.Aspxor.139264.F
EmsisoftGen:Variant.Symmi.45094 (B)
ComodoTrojWare.Win32.Kuluoz.EML@5e75r3
ZillyaWorm.Aspxor.Win32.2371
TrendMicroBKDR_KULOUZ.SMXC
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Wonton-G
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.45094
JiangminWorm/Aspxor.ka
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.60B
MicrosoftTrojanDownloader:Win32/Kuluoz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kuluoz.R115238
McAfeePacked-BP!1DE0502F12DB
MAXmalware (ai score=80)
VBA32Worm.Aspxor
MalwarebytesMalware.AI.2435841238
TrendMicro-HouseCallBKDR_KULOUZ.SMXC
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexWorm.Aspxor!WlWylUPMK5Q
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CIBL!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Symmi.45094?

Symmi.45094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment