Malware

Symmi.39870 removal tips

Malware Removal

The Symmi.39870 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.39870 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Hindi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Symmi.39870?


File Info:

name: 4E3671C6438FD7C2F6C9.mlw
path: /opt/CAPEv2/storage/binaries/f7519940614e6633d4dfc759ede3cb27df17e58dcb019fa11d9392a48f34e2a7
crc32: 0339B9FD
md5: 4e3671c6438fd7c2f6c99114f57c03a8
sha1: 0a078e0705e024ea2ed74ec2f263e4ad6c1cd9b4
sha256: f7519940614e6633d4dfc759ede3cb27df17e58dcb019fa11d9392a48f34e2a7
sha512: add0ac4892e3b7eb5d560c56545d8c3e80138088a1f6de0572fcb8cd01f2530d267abcadbd6c029b754915e05a3b057567cf323a36600deeeb2d1ec6441baa27
ssdeep: 6144:sR+f6qsgfteNBMKceP/45w+oYav0yAiWDUF:1f6qMkKcwB+hUQiW4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6644B1C53C4A85BD4FA1DF93A5263203BCA0E357764ADDF312CB813B677650E98839A
sha3_384: 5d42589d512f116da7879b3674271add55346aa2d240424265fc1afa59c5a280aed43ccdf3dbd3852a741668a84caa9b
ep_bytes: 68bcbb4300e8eeffffff000000000000
timestamp: 2013-10-22 14:25:06

Version Info:

Translation: 0x0439 0x04b0
Comments: IO MI RICORDO
CompanyName: QUATTRO E 1
FileDescription: Mitlachender6
LegalCopyright: Diagnoseprogramms7
LegalTrademarks: Radioempfängertechnik
ProductName: Bauerninspektionen
FileVersion: 3.03.0008
ProductVersion: 3.03.0008
InternalName: Gomox1
OriginalFilename: Gomox1.exe

Symmi.39870 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.2401
MicroWorld-eScanGen:Variant.Symmi.39870
FireEyeGeneric.mg.4e3671c6438fd7c2
CAT-QuickHealVirTool.VBInject.LE3
ALYacGen:Variant.Symmi.39870
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.151603
Sangfor[MICROSOFT VISUAL BASIC 5.0]
CrowdStrikewin/malicious_confidence_100% (W)
K7GWSpyware ( 0055e3db1 )
K7AntiVirusSpyware ( 0055e3db1 )
BitDefenderThetaGen:NN.ZevbaF.34592.tm0@aKvdtJcG
VirITTrojan.Win32.X-VBCrypt.BJN
CyrenW32/Gosys.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.qmnv
BitDefenderGen:Variant.Symmi.39870
NANO-AntivirusTrojan.Win32.Zbot.dwunnu
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10c704dc
Ad-AwareGen:Variant.Symmi.39870
EmsisoftGen:Variant.Symmi.39870 (B)
VIPREGen:Variant.Symmi.39870
McAfee-GW-EditionGenericR-ELS!4E3671C6438F
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.39870
JiangminTrojanSpy.Zbot.ecni
WebrootW32.Infostealer.Zeus
GoogleDetected
AviraHEUR/AGEN.1249443
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MDA.B52502.X1313
McAfeeGenericR-ELS!4E3671C6438F
MAXmalware (ai score=88)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Zbot
YandexTrojanSpy.Zbot!vRKKVqJaHWQ
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dorkbot.BAA!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.6438fd
PandaTrj/CI.A

How to remove Symmi.39870?

Symmi.39870 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment