Malware

Symmi.13445 removal tips

Malware Removal

The Symmi.13445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.13445 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • CAPE detected the Andromeda malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Symmi.13445?


File Info:

name: E049223F24BD4F57FF47.mlw
path: /opt/CAPEv2/storage/binaries/fd6e5cbda8c26145ed8193fa7d4190c2ba5fce5684b7cc7b373cee3ddc8ad883
crc32: 3F9BC5F5
md5: e049223f24bd4f57ff479e8213f2d96a
sha1: 2be8ec7174686a40726b71490fdcf8659223e4b6
sha256: fd6e5cbda8c26145ed8193fa7d4190c2ba5fce5684b7cc7b373cee3ddc8ad883
sha512: bdd10b2fd7c0982b33fa3d43f1d78b97ac3694236f503a911bdc0add1212e036be276e612483074797288825e22cbeb6cdd7f9d529afe53135e4bfb5c83ec0b2
ssdeep: 1536:cOdW7EUYoXYUw/A4qi/9dL63thexxywYV5cYXcKMqQ:cOg7EUXXY7/AInAthexxypRJMX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF739E16AF280CBBD07707B619732B8287F4B8329E25459327C0EECE5C95A82D937757
sha3_384: c4c911dc2c90753b17718590e76b0cdfa0899016de4062e20542647027034a724f6e4ac1a5a2f26837670b1dde0b987f
ep_bytes: 558bec83ec34535657892dacf5400060
timestamp: 2012-05-15 10:51:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Entertainment Pack FreeCell Game
FileVersion: 5.00.2135.1
InternalName: freecell
LegalCopyright: Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename: freecell
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.00.2135.1
Translation: 0x0409 0x04b0

Symmi.13445 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.13445
FireEyeGeneric.mg.e049223f24bd4f57
McAfeePWS-Zbot.gen.bex
CylanceUnsafe
VIPRETrojan.Win32.Reveton.ca (v)
SangforTrojan.Win32.Krap.iu
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Gamarue.a6bbdcf4
K7GWTrojan ( 0040f02a1 )
K7AntiVirusTrojan ( 0040f02a1 )
VirITTrojan.Win32.Defiler.G
CyrenW32/Zbot.FO.gen!Eldorado
SymantecPacked.Generic.362
ESET-NOD32a variant of Win32/Kryptik.AFPS
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyPacked.Win32.Krap.iu
BitDefenderGen:Variant.Symmi.13445
NANO-AntivirusTrojan.Win32.Dwn.dwtflk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentMalware.Win32.Gencirc.114c5b07
Ad-AwareGen:Variant.Symmi.13445
EmsisoftGen:Variant.Symmi.13445 (B)
ComodoTrojWare.Win32.Kryptik.ASR@4oc4x0
DrWebBackDoor.Andromeda.22
ZillyaTrojan.Kryptik.Win32.239122
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionPWS-Zbot.gen.bex
SophosMal/Generic-R + Mal/Zbot-KK
Paloaltogeneric.ml
GDataGen:Variant.Symmi.13445
JiangminPacked.Krap.gqbk
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.1EFAA3
KingsoftWin32.Heur.KVM011.a.(kcloud)
MicrosoftWorm:Win32/Gamarue.I
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R24299
Acronissuspicious
MAXmalware (ai score=99)
VBA32BScope.Trojan-Proxy.Wintu.1161
MalwarebytesMalware.AI.2644934551
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
RisingRansom.Reveton!8.F2 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Lockscreen.LOA!tr
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.f24bd4
PandaBck/Qbot.AO
MaxSecureTrojan.Packed.Krap.iu

How to remove Symmi.13445?

Symmi.13445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment