Malware

Symmi.838 malicious file

Malware Removal

The Symmi.838 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.838 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Symmi.838?


File Info:

name: C1CDCA83AF89EE4228C5.mlw
path: /opt/CAPEv2/storage/binaries/6437dca116f5febcb48d4190c1322a21467d4009e81af689da7383d7520c2652
crc32: D6867DFF
md5: c1cdca83af89ee4228c578c8774ab576
sha1: 2db41e8b19f4c1bbb10538b34adcd2062fa17694
sha256: 6437dca116f5febcb48d4190c1322a21467d4009e81af689da7383d7520c2652
sha512: 041bbe741d3676bf20753eb9e591a49a6e499ea03825e592253ba628b3e67659c40d0282ac21905d685f77ca2ed7d5ec2f760fe121cd44f1c8975fc67a52a3d1
ssdeep: 6144:AN3jmDTokkGMonFl+Ahrw42jhEHvZqhtaHMVHaeuqifMrwm/:4zCToktNnC+wtwBqhAHOWc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F54F0813698DA00E5595034EE51E0FE2D25BCE4DFA1A9EB7AC23F0F3475AC4E4B8752
sha3_384: ac47788a39f54881177bd5255cd8107bf8e8fafbf17cad1eb7a22227aee1e1c453cca65abb5891e7983e4aaebc8860e5
ep_bytes: 83ec1c566a00ff15103044008d442408
timestamp: 2012-08-15 12:21:23

Version Info:

LegalCopyright: ThinkPenguin.com 2007-2009
CompanyName: ThinkPenguin.com
FileDescription: Difficulties Ultra
FileVersion: 1.2.0
ProductVersion: 1.2.0
InternalName: Difficulties Ultra
OriginalFilename: difficultiesultra.exe
ProductName: Difficulties Ultra
Translation: 0x0809 0x04b0

Symmi.838 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c1cdca83af89ee42
CAT-QuickHealTrojanPWS.Zbot.Y
SkyhighBehavesLike.Win32.Generic.dm
ALYacGen:Variant.Symmi.838
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Zbot.Win32.74441
AlibabaTrojanPSW:Win32/Kryptik.2c14b7b6
Cybereasonmalicious.b19f4c
ArcabitTrojan.Symmi.838
BitDefenderThetaGen:NN.ZexaF.36680.rq1@a0wZmrmi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AKIJ
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Symmi.838
NANO-AntivirusTrojan.Win32.Zbot.xzdkt
MicroWorld-eScanGen:Variant.Symmi.838
AvastWin32:Agent-APKN [Trj]
TencentWin32.Trojan.Crypt.Qgil
EmsisoftGen:Variant.Symmi.838 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PWS.Panda.1949
VIPREGen:Variant.Symmi.838
TrendMicroCryp_Necurs-1
SophosMal/EncPk-AGK
IkarusTrojan-Dropper.Win32.Injector
JiangminTrojanSpy.Zbot.catv
WebrootW32.Trojan.Gen
VaristW32/Zbot.QS.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Kryptik.AKIM@4qpobz
MicrosoftPWS:Win32/Zbot!CI
ViRobotTrojan.Win32.A.Zbot.281088.AM
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Symmi.838
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R32745
McAfeeGeneric BackDoor.adp
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
Cylanceunsafe
PandaTrj/Pacrypt.C
TrendMicro-HouseCallCryp_Necurs-1
RisingTrojan.Necurs!8.B03 (TFE:2:LJWxNa94Q7B)
SentinelOneStatic AI – Malicious PE
FortinetW32/Androm.DW!tr
AVGWin32:Agent-APKN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Symmi.838?

Symmi.838 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment