Malware

Symmi.70964 (file analysis)

Malware Removal

The Symmi.70964 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.70964 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Symmi.70964?


File Info:

crc32: C8E10786
md5: a692ca49ec6be9ae2f25f6a8c15a8ffb
name: A692CA49EC6BE9AE2F25F6A8C15A8FFB.mlw
sha1: f0cc930b6c6e4e4078be1d85de4ac82379ccecf2
sha256: 9167a15a6852c3acd4fb6dfd2ae241a2d6ff4bfc72cda358446d191d405195aa
sha512: 0701bfffd035930c16871e4de1d056f0a30f8836488c77fadb2cd3b1fdae93454920c2ea822222f16e19adabb937410bbdea296580a15a17c1a7eed013f88ffd
ssdeep: 6144:T7B6a+TZTU6v3CmKq7b02l+UP0P0q6LNHR2o4SKt:T7B6ZTZTFvSmjxH0P0q6pH4o4SKt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. xfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffd
InternalName: Programming
CompanyName: xfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffd
PrivateBuild: 8.9.6.2
LegalTrademarks: Copyright xa9. All rights reserved. xfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffdxfffd xfffdxfffdxfffdxfffdxfffdxfffdxfffd
Comments: Petitions Haphazard
ProductName: Programming
ProductVersion: 8.9.6.2
FileDescription: Petitions Haphazard
Translation: 0x0409 0x04b0

Symmi.70964 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005031f11 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.70964
ZillyaTrojan.Kryptik.Win32.2600588
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005031f11 )
Cybereasonmalicious.9ec6be
ESET-NOD32a variant of Win32/Kryptik.HELN
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crusis.aqg
BitDefenderGen:Variant.Symmi.70964
NANO-AntivirusTrojan.Win32.Crusis.evdkbf
MicroWorld-eScanGen:Variant.Symmi.70964
TencentWin32.Trojan.Crusis.Lndy
Ad-AwareGen:Variant.Symmi.70964
SophosMal/Generic-S
ComodoMalware@#4d4m6zwaaz1o
BitDefenderThetaGen:NN.ZexaF.34628.wq0@aqwDzAii
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.a692ca49ec6be9ae
EmsisoftGen:Variant.Symmi.70964 (B)
JiangminTrojan.Crusis.oy
AviraHEUR/AGEN.1114515
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Genasom
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.70964
Acronissuspicious
McAfeeArtemis!A692CA49EC6B
MAXmalware (ai score=99)
VBA32BScope.TrojanSpy.Ursnif
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME
RisingRansom.Crusis!8.5724 (CLOUD)
YandexTrojan.Crusis!+TEWsUiezl0
FortinetW32/Kryptik.CRFT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CrySiS.HgIASOgA

How to remove Symmi.70964?

Symmi.70964 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment