Malware

Symmi.21812 (B) removal

Malware Removal

The Symmi.21812 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.21812 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Symmi.21812 (B)?


File Info:

name: 4654FEF3AE088D726A1B.mlw
path: /opt/CAPEv2/storage/binaries/e9a3336a2e237f65f1b39612c6fec19e027eda31c4d23b1348008b23f678eab6
crc32: 4144A02F
md5: 4654fef3ae088d726a1b20e6f5a481c5
sha1: 461bdb27bb08149ab39df00d5f8533f66fa4a583
sha256: e9a3336a2e237f65f1b39612c6fec19e027eda31c4d23b1348008b23f678eab6
sha512: ef60d452d0fb24eef38c2369d13cdb46b19bc17afbb046fc881d7ca78a0662d7b9670c90e3bca365e83210dd80e44bef891633d7e7b0254abc1d36641fffee2e
ssdeep: 3072:pJsnFgcQPGDQicxBrGB+GJuyGI/YL1oxR8oXQ1:pJstQP4aGjQyM1yBg1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13314A43A7290A73ED425C7F87CAE83A4502DAD3511C5A417F7C12B1A72E2AF79220767
sha3_384: fc535158bf41c607d2d069eb40bad157901bdf7c58f4e471f8be7085ad244615e7e2f195882f72328bcadd086be8f704
ep_bytes: 6850434000e8f0ffffff000000000000
timestamp: 2012-03-14 07:48:39

Version Info:

FileVersion: 3.00
ProductVersion: 3.00
Translation: 0x0409 0x04b0

Symmi.21812 (B) also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lv1H
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.21812
FireEyeGeneric.mg.4654fef3ae088d72
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGeneric VB.kk
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1517040
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.630f1684
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.mm0@a4bzilbi
VirITTrojan.Win32.SHeur4.UJB
Paloaltogeneric.ml
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATG
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMD1
AvastWin32:VB-ABRW [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dgkf
BitDefenderGen:Variant.Symmi.21812
NANO-AntivirusTrojan.Win32.VB.cihugc
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Symmi.21812 (B)
BaiduWin32.Worm.Pronny.d
F-SecureWorm.WORM/VBNA.bztzre
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Symmi.21812
TrendMicroWORM_VOBFUS.SMD1
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-AC
IkarusWorm.Win32.Vobfus
MAXmalware (ai score=100)
JiangminTrojan/Vbobf.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/VBNA.bztzre
VaristW32/Vobfus.AD.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.Vobfus.dgkf
MicrosoftWorm:Win32/Vobfus.gen!R
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Symmi.D5534
ViRobotWorm.Win32.A.WBNA.200704.BQ
ZoneAlarmWorm.Win32.Vobfus.dgkf
GDataGen:Variant.Symmi.21812
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R22840
Acronissuspicious
VBA32BScope.Trojan.VB.Onechki
ALYacGen:Variant.Symmi.21812
TACHYONWorm/W32.Vobfus.200704.C
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.Autorun!8.50 (TFE:3:NUyINK2O6IT)
YandexTrojan.GenAsa!hW3s5gOKwOE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABRW [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.79c03e1a

How to remove Symmi.21812 (B)?

Symmi.21812 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment