Malware

Application.Symmi.11352 (B) removal instruction

Malware Removal

The Application.Symmi.11352 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Symmi.11352 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Symmi.11352 (B)?


File Info:

name: E196B5FD5A591228D633.mlw
path: /opt/CAPEv2/storage/binaries/cde1e4309012a70a6ff8c6a6b53a06759356d0ce2ad2364fdc620477b8abc454
crc32: 50A2E02B
md5: e196b5fd5a591228d6338b0419b712c5
sha1: 42c9b201f6c62131cb3b1f0280c42ca98fe35d9d
sha256: cde1e4309012a70a6ff8c6a6b53a06759356d0ce2ad2364fdc620477b8abc454
sha512: 465fffef3c1f58a72e079702bb9d0f68415fcee520be6aa857b527b7e0004f0f9df3d4aef97565eab3f8bac11093cb04d6e9e800f36dd56821721d8ffce689af
ssdeep: 3072:Yddauqj2r0yqjdQGn5V8XyusBAFMih89dQwLhBc/WF:Si9jdQGn/qyrAFjynLc/k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19014B5397241E73EE425C7F9289A83A0406DAD3611D5A41BFBC25B1A36F19F7D3207A3
sha3_384: 6c3bd341794f86cc1ea5bcc7841dc98a39dc37ccb6ef9457d0885adfa0d6fa5a9c4c54082d7e01199173a7eee7dc4b4b
ep_bytes: 68504a4000e8f0ffffff000040000000
timestamp: 2012-02-13 22:02:39

Version Info:

Translation: 0x0409 0x04b0
ProductName: xcWFPZx
FileVersion: 1.00
ProductVersion: 1.00
InternalName: XjyqhPvB
OriginalFilename: XjyqhPvB.exe

Application.Symmi.11352 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Symmi.11352
FireEyeGeneric.mg.e196b5fd5a591228
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eu
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
ArcabitTrojan.Application.Symmi.D2C58
BaiduWin32.Trojan.Jorik.e
VirITTrojan.Win32.SHeur4.QHB
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ASG
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfle
BitDefenderGen:Variant.Application.Symmi.11352
NANO-AntivirusTrojan.Win32.Jorik.cmtiui
AvastWin32:AutoRun-CQP [Wrm]
TencentWorm.Win32.Vobfus.kaa
TACHYONWorm/W32.Vobfus.208896.C
EmsisoftGen:Variant.Application.Symmi.11352 (B)
F-SecureTrojan.TR/Jorik.ejmj
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-B
IkarusWorm.Vobfus
GoogleDetected
AviraTR/Jorik.ejmj
VaristW32/Vobfus.AI.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.VB.AVA@4paxk7
MicrosoftWorm:Win32/Vobfus!pz
ViRobotWorm.Win32.A.WBNA.208896.L
ZoneAlarmWorm.Win32.Vobfus.dfle
GDataGen:Variant.Application.Symmi.11352
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R20724
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.mm0@aC7Uieli
ALYacGen:Variant.Application.Symmi.11352
MAXmalware (ai score=70)
VBA32BScope.Trojan.VB.Diple.01583
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!uxqnusyVOGs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.CM!tr
AVGWin32:AutoRun-CQP [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.4c944093

How to remove Application.Symmi.11352 (B)?

Application.Symmi.11352 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment