Malware

What is “Symmi.5142”?

Malware Removal

The Symmi.5142 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.5142 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Symmi.5142?


File Info:

name: E4130892379F889C32AC.mlw
path: /opt/CAPEv2/storage/binaries/aa0c0d34020a2e614a613df76c08740d09264cec21f084a769aff3f049995231
crc32: D3C2BA19
md5: e4130892379f889c32ac151e0b7d4355
sha1: 9eb7828ee8e406ed81070b2f79926d2bd9f61fb1
sha256: aa0c0d34020a2e614a613df76c08740d09264cec21f084a769aff3f049995231
sha512: 8f9675761a9397730f7ec60fa24f366b1bf874238db2c1e85df5be9dab0eb316b979712fab22794ca5cc1f038dc5ae22829342523f5efca4d94e5730d7d72297
ssdeep: 3072:sIjYWOyhB/aYQxwca9EjmAa5MAWKC35AJU0Km4xZqMTwAeK2JjXv:sIqs/gwcaejy+l58U0KeUZbSj/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8141252D5575CF6D98E0BFCC8A5B72D4B7E7EA25CA1C4FCCC810D89A41A30028A8AB5
sha3_384: 3001a3121f9b18b7c569d3f5c94bed5a31c7ad6d464f0011d125dfc99f512e6c6a30d45b27517a308454b2814daa41b4
ep_bytes: 558bec83c4f0b868424000e8e4f3ffff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: ICQ, LLC.
FileDescription: ICQ
FileVersion: 7.8.0.6800
InternalName: ICQ
LegalCopyright: Copyright (c) 1998-2010 ICQ, LLC.
LegalTrademarks:
OriginalFilename: ICQ.exe
ProductName: ICQ
ProductVersion: 7.8.0.6800
DistId: 30015
Translation: 0x0409 0x04b0

Symmi.5142 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.lzwQ
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e4130892379f889c
McAfeePWS-Zbot.gen.aow
CylanceUnsafe
VIPRETrojan.Win32.Ransomware.B (v)
SangforTrojan.Win32.Symmi.frlB
K7AntiVirusTrojan ( 0040f2c31 )
AlibabaVirTool:Win32/Obfuscator.9da87a4a
K7GWTrojan ( 0040f2c31 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Panda.DOJ
SymantecPacked.Generic.392
ESET-NOD32a variant of Win32/Injector.XYG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-62335
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.5142
NANO-AntivirusTrojan.Win32.DownLoad3.dglgqt
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.Symmi.5142
AvastWin32:Crypt-OAW [Trj]
TencentMalware.Win32.Gencirc.114c0a14
Ad-AwareGen:Variant.Symmi.5142
ComodoTrojWare.Win32.Kryptik.NEWA@4rfpbi
DrWebTrojan.PWS.Panda.2401
ZillyaTrojan.Injector.Win32.151704
TrendMicroTSPY_ZBOT.SM16
EmsisoftGen:Variant.Symmi.5142 (B)
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Symmi.5142
JiangminTrojan.Generic.dxegw
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.ZPACK.Gen8
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.150F52
KingsoftWin32.Troj.Zbot.gr.(kcloud)
ArcabitTrojan.Symmi.D1416
MicrosoftPWS:Win32/Zbot!CI
AhnLab-V3Spyware/Win32.Zbot.R41152
BitDefenderThetaGen:NN.ZelphiF.34212.mG1@a8AZC3ci
ALYacGen:Variant.Symmi.5142
VBA32Malware-Cryptor.Inject.gen
TrendMicro-HouseCallTSPY_ZBOT.SM16
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Injector!V8fDumhXklg
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.WCT!tr
AVGWin32:Crypt-OAW [Trj]
PandaTrj/Velphi.b

How to remove Symmi.5142?

Symmi.5142 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment