Malware

About “Symmi.68808 (B)” infection

Malware Removal

The Symmi.68808 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.68808 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Connects to Tor Hidden Services through a Tor gateway
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io
qcuikaiye577q3p2.aw49f4j3n26.com
qcuikaiye577q3p2.dfj3d8w3n27.com
qcuikaiye577q3p2.tor2web.blutmagie.de
qcuikaiye577q3p2.tor2web.fi

How to determine Symmi.68808 (B)?


File Info:

crc32: CE489FF2
md5: 65f4c345c02a967fbd422abdff961466
name: 65F4C345C02A967FBD422ABDFF961466.mlw
sha1: 1c1fba82778367cd7a3d8dd67f302260d2c7f138
sha256: bdb6d0149e06e8d3b4c36d29f41a11400230b839fe814141462bd838ffb84454
sha512: e6f1884477c08a734efc4bd3b68dbc8481b9f3d95165e85af7555489ffb7c5bf2805c1db82497a2ae824428051a7a4f7f9506ec664aa036b9f15fb7eef77564b
ssdeep: 24576:Gtb20pkaCqT5TBWgNQ7aCf0jdIiwWUHTLgd+Pmc6A:zVg5tQ7aCxzTs85
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Symmi.68808 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Multi.Generic.4!c
CynetMalicious (score: 99)
ALYacGen:Variant.Symmi.68808
CylanceUnsafe
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.5c02a9
SymantecTrojan.Gen.2
ESET-NOD32Win32/Filecoder.TeslaCrypt.A
APEXMalicious
AvastWin32:TeslaCrypt-D [Trj]
ClamAVWin.Trojan.TeslaCrypt-2
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Symmi.68808
NANO-AntivirusTrojan.Win32.Bitman.dqzkil
MicroWorld-eScanGen:Variant.Symmi.68808
Ad-AwareGen:Variant.Symmi.68808
SophosTroj/Wonton-QM
BitDefenderThetaGen:NN.ZexaF.34142.ymW@a0wRNXji
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPTESLA.SM
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGen:Variant.Symmi.68808
EmsisoftGen:Variant.Symmi.68808 (B)
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1126908
eGambitUnsafe.AI_Score_82%
Antiy-AVLTrojan/Generic.ASMalwS.104F050
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.Symmi.D10CC8
GDataGen:Variant.Symmi.68808 (2x)
AhnLab-V3Trojan/Win32.Cryptolocker.R144630
McAfeeArtemis!65F4C345C02A
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_CRYPTESLA.SM
RisingTrojan.Generic@ML.91 (RDML:EsM26vwGbg25wOoT9oW9gA)
IkarusTrojan-Ransom.TeslaCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Wonton.QM!tr
AVGWin32:TeslaCrypt-D [Trj]
Paloaltogeneric.ml

How to remove Symmi.68808 (B)?

Symmi.68808 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment