Malware

About “Symmi.17583” infection

Malware Removal

The Symmi.17583 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.17583 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Symmi.17583?


File Info:

name: CB4BD9000D816B884E17.mlw
path: /opt/CAPEv2/storage/binaries/07cae6fb2fe2f59a0e23b98e7de93bc73ba83a4ddd19897df6194dc0bbe37da7
crc32: 022C2863
md5: cb4bd9000d816b884e1742a8ede34650
sha1: 2c4acfd23d83f949a30d1c2f975e0031d953082c
sha256: 07cae6fb2fe2f59a0e23b98e7de93bc73ba83a4ddd19897df6194dc0bbe37da7
sha512: 4a7a447d5b8a7a0a659bf225be088a3aa38325d3b9fd22f720c550793fe1c23794d7a0127c521146e7d46200feae07c9a19ffeac182060e07949b3e0074b5b8a
ssdeep: 6144:rMMFLegDb6egS82HT0wXVbIsGuhMtRoG1HUjlyqSIP6c:oY7LgSXHnl0lBtRGjkqry
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C5402107C848FA9C2D4DE73C297B520A267E8557222DB5FE1DAD37A2819390CF5374D
sha3_384: 8d897681dca8021625b15ef88e603f7991b29da0b341b66e3a5073267bc803c772194bfac3d6a9e22c1a176e2119d20b
ep_bytes: 558bec6aff68c8114000681524400064
timestamp: 2001-01-10 02:43:56

Version Info:

CompanyName: Wvwl Jbxb
FileDescription: OxdicSurwbrvxz Ainzue Tnsrewxz
FileVersion:
InternalName: Oxdic
LegalCopyright: Copyright Wvwl Jbxb
OriginalFilename: Oxdic.exe
ProductName: Oxdic
ProductVersion:
Translation: 0x0409 0x04b0

Symmi.17583 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.cb4bd9000d816b88
McAfeePWS-Zbot-FASG!CB4BD9000D81
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Kryptik.543cd283
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AZKB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.lbdl
BitDefenderGen:Variant.Symmi.17583
NANO-AntivirusTrojan.Win32.Zbot.bppyfw
MicroWorld-eScanGen:Variant.Symmi.17583
AvastFileRepMalware
TencentWin32.Trojan-spy.Zbot.Szbn
Ad-AwareGen:Variant.Symmi.17583
EmsisoftGen:Variant.Symmi.17583 (B)
ComodoMalware@#3w12bog33heaf
DrWebTrojan.PWS.Panda.3734
ZillyaTrojan.Zbot.Win32.169941
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionPWS-Zbot-FASG!CB4BD9000D81
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Symmi.17583
JiangminTrojanSpy.Zbot.fmae
WebrootW32.Infostealer.Zeus
AviraBDS/ZeroAccess.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.1BEC7D
KingsoftWin32.Troj.Zbot.lb.(kcloud)
ArcabitTrojan.Symmi.D44AF
ZoneAlarmTrojan-Spy.Win32.Zbot.lbdl
MicrosoftPWS:Win32/Zbot!GO
TACHYONTrojan-Spy/W32.ZBot.289280.AC
AhnLab-V3Spyware/Win32.Zbot.C166991
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.ruW@aWHvgegi
ALYacGen:Variant.Symmi.17583
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesMalware.Heuristic.1008
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!xmZPBAbnnFo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Kryptik.AZWE!tr
AVGFileRepMalware
Cybereasonmalicious.00d816
PandaGeneric Malware

How to remove Symmi.17583?

Symmi.17583 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment