Malware

Symmi.41965 removal guide

Malware Removal

The Symmi.41965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.41965 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Symmi.41965?


File Info:

name: 0707512FD082BD68E5BB.mlw
path: /opt/CAPEv2/storage/binaries/e9b9c8caa4f7f8374b4069634765bf088934079b75c5b9151601d83b2d4a2f31
crc32: 9315467D
md5: 0707512fd082bd68e5bb8ad85c31223b
sha1: 00884ca0cf932db96efc57c7f3ca3a693485b1f1
sha256: e9b9c8caa4f7f8374b4069634765bf088934079b75c5b9151601d83b2d4a2f31
sha512: 6dbe538e14df7cf6277c979c2fb611f18c6def646e85177dff28e0a99a830b9e31cb9458969b1c050ef666179a894417297fd14011e5fb74b56fea79b0a6524c
ssdeep: 6144:q1o/rZ8KjVetvfFVz9G/j9+FGQB2AaPSSWe49LIyMrN3F1+:Wo/rvjIfNlGo2AaPhe9LIyMRVM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1627401AE7A19D836C01C0D344A13DBFB5F705D509D558A0B7AB1FF1E3CBA291BE6009A
sha3_384: f09f1575369c98040923a1b8d454e76b056dfc5278eb63ea1aeb0d811ea09b36c81db11749f6b2cb2231fb3da6c6b47b
ep_bytes: 60be007046008dbe00a0f9ff57eb0b90
timestamp: 2014-05-07 05:37:30

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Symmi.41965 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.8566
MicroWorld-eScanGen:Variant.Symmi.41965
FireEyeGeneric.mg.0707512fd082bd68
ALYacGen:Variant.Symmi.41965
MalwarebytesPUP.Optional.ChinAd
ZillyaTrojan.Badur.Win32.6842
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004c746b1 )
K7GWTrojan-Downloader ( 004c746b1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34084.wmLfa0t@N7lb
CyrenW32/Agent.EW.gen!Eldorado
SymantecInfostealer.Bankeiya
ESET-NOD32a variant of Win32/TrojanDownloader.FlyStudio.BT
ClamAVWin.Malware.Atrm-9862786-0
KasperskyTrojan-Downloader.Win32.Agent.xxypzo
BitDefenderGen:Variant.Symmi.41965
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:Agent-ATRM [Trj]
TencentMalware.Win32.Gencirc.10b8777e
Ad-AwareGen:Variant.Symmi.41965
EmsisoftGen:Variant.Symmi.41965 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Dloadr-CF
IkarusBackdoor.Win32.Hupigon
GDataWin32.Application.PUPStudio.A
JiangminTrojan/Generic.fewn
AviraHEUR/AGEN.1125448
Antiy-AVLTrojan/Generic.ASMalwS.1CC82DD
ArcabitTrojan.Symmi.DA3ED
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Blackhole.C125793
Acronissuspicious
McAfeeGenericRXAA-AA!0707512FD082
MAXmalware (ai score=85)
VBA32Trojan-Downloader.EIC.7121
CylanceUnsafe
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Agent-ATRM [Trj]
Cybereasonmalicious.fd082b

How to remove Symmi.41965?

Symmi.41965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment