Malware

How to remove “Symmi.26024”?

Malware Removal

The Symmi.26024 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.26024 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Andromeda malware family
  • Anomalous binary characteristics

How to determine Symmi.26024?


File Info:

name: A60EF9C8FABACBD913A8.mlw
path: /opt/CAPEv2/storage/binaries/de6d6b245b4764383c274e0c12ea3d4ab7760ada112540c0d8938a35376010fd
crc32: E93CFA90
md5: a60ef9c8fabacbd913a8d9a20bb4a496
sha1: 0b146280b36f3c1da5d37d3733c68dd3532dfa13
sha256: de6d6b245b4764383c274e0c12ea3d4ab7760ada112540c0d8938a35376010fd
sha512: cfd7542c3df74f49fe7d9d9278fb9688dbec7cf262e4664f8690c7186b53587fa773b2a04903ae78382ae21754f3bfdf3150f000ff66357a6cf0e2fa316e38c7
ssdeep: 3072:RespIBoWxCM9qKU2vDebC6P79kiq5tvx/LUY7oEM2IfCGm7I9jnBhhk+HQSshzbS:ResCjlTUe6TqiYn8cl0nSSshzyfrD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5841270BBD695F1C6D2A1F032AB49515B7F12A32BC272B3C7650C0E6F70AF40D6A616
sha3_384: f1051ae8d6ec7938c742931a8ffdc47b68317e68d9475f85a434327d3f1524c324c8ed259943b725ce1d6298dd929505
ep_bytes: 558bec6aff68c0704000685040400064
timestamp: 2005-02-11 06:50:56

Version Info:

Comments: Gezera
CompanyName: Hause
FileDescription: Mikega
FileVersion: 2, 1, 3, 2
InternalName: Ragiza
LegalCopyright: Copyright Misejka© 2013
LegalTrademarks: Gioka©
OriginalFilename: Magez
PrivateBuild: Kizbow
ProductName: Bigalov
ProductVersion: 5, 1, 8, 4
SpecialBuild: Makanz
Translation: 0x0409 0x04b0

Symmi.26024 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lWCf
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.26024
ClamAVWin.Malware.Gamarue-7001972-0
FireEyeGeneric.mg.a60ef9c8fabacbd9
CAT-QuickHealWorm.Gamarue.B
McAfeeGeneric.gl.gen.a
CylanceUnsafe
VIPREGen:Variant.Symmi.26024
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f6db1 )
K7GWTrojan ( 0040f6db1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Wauchos.a
VirITTrojan.Win32.Crypt.CEJE
CyrenW32/Gamarue.C.gen!Eldorado
SymantecPacked.Dromedan!gen7
ESET-NOD32a variant of Win32/Injector.AIHW
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.iech
BitDefenderGen:Variant.Symmi.26024
NANO-AntivirusTrojan.Win32.RiskGen.csspqt
AvastWin32:Patched-AFV [Trj]
TencentTrojan.Win32.Injector.h
Ad-AwareGen:Variant.Symmi.26024
EmsisoftGen:Variant.Symmi.26024 (B)
ComodoTrojWare.Win32.Kryptik.FOER@4xwm8a
DrWebTrojan.Packed.24313
ZillyaTrojan.Injector.Win32.202482
TrendMicroWORM_GAMARUE.SMJ
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fm
SophosML/PE-A + Mal/Inject-EA
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Injector.aqsq
WebrootW32.Malware.gen
AviraTR/Rogue.195211
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.24D
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftWorm:Win32/Gamarue
ViRobotTrojan.Win32.Inject.130053
GDataGen:Variant.Symmi.26024
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R68899
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.xq0@audmcLhO
ALYacGen:Variant.Symmi.26024
VBA32Trojan.Agent
MalwarebytesVirut.Virus.FileInfector.DDS
TrendMicro-HouseCallWORM_GAMARUE.SMJ
RisingTrojan.Injector!1.9C6E (CLASSIC)
YandexTrojan.GenAsa!zSj6AKIt/w8
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BBYD!tr
AVGWin32:Patched-AFV [Trj]
Cybereasonmalicious.8fabac
PandaTrj/Genetic.gen

How to remove Symmi.26024?

Symmi.26024 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment