Malware

Symmi.42239 malicious file

Malware Removal

The Symmi.42239 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.42239 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Symmi.42239?


File Info:

name: ABAA5FA405637B243D21.mlw
path: /opt/CAPEv2/storage/binaries/9c2dce03f7962e2a36dddebc3b4c1af519ede41d7c5daea2d5f1f0ca9c2f8618
crc32: BED51B1C
md5: abaa5fa405637b243d216e3713fa81c9
sha1: 24c8b743f3748e2efb2dbf840b5e5e1fa0b9cc9a
sha256: 9c2dce03f7962e2a36dddebc3b4c1af519ede41d7c5daea2d5f1f0ca9c2f8618
sha512: 58254cc8f5fba4c527c01e773f4b6e103efb36f94fc880f92f4a25e7ea20470764250ec61b5c0413f607374a3d51ef2a29585e8830d344709c7febadb6b13e84
ssdeep: 768:RegMK7v8qo4EJvpzITgRWs9B7N8b/gWmbn5SdJiPY/6RQ+y0ZEhW1AUrH5b7CAXH:ReMvw4EbVWsryDgpXuauAXf6An9Kbg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B63D612F614C03BE516D2F26D39A29A5126BD3607E19D43B689BF7C38720D3A9F0787
sha3_384: 2c6cde2b2c8ea1feb2871c3fb5d65e09aec1bd1aa5906776e94a1bac854de78b43644fc494f449a2bb3adb48630057d7
ep_bytes: 68f01a4000e8eeffffff000000000000
timestamp: 2013-08-13 18:42:30

Version Info:

Translation: 0x0409 0x04b0

Symmi.42239 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lWQx
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Symmi.42239
ClamAVWin.Trojan.VBGeneric-9850916-0
FireEyeGeneric.mg.abaa5fa405637b24
CAT-QuickHealTrojan.Beebone.D
SkyhighW32/Worm-AAEH.c!ABAA5FA40563
ALYacGen:Variant.Symmi.42239
Cylanceunsafe
ZillyaTrojan.Fraud.Win32.1696
SangforDownloader.Win32.Beebone.V3rb
K7AntiVirusTrojan ( 005042e71 )
AlibabaTrojan:Win32/Fraud.012c241b
K7GWTrojan ( 005042e71 )
Cybereasonmalicious.3f3748
ArcabitTrojan.Symmi.DA4FF
BitDefenderThetaAI:Packer.6488E6A520
SymantecW32.Changeup!gen46
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AWKD
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Fraud.ezq
BitDefenderGen:Variant.Symmi.42239
NANO-AntivirusTrojan.Win32.Fraud.exofay
AvastWin32:Downloader-VGN [Trj]
TencentWin32.Trojan.Fraud.Rnkl
EmsisoftGen:Variant.Symmi.42239 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/FakeAV.owle
DrWebTrojan.DownLoader9.33267
VIPREGen:Variant.Symmi.42239
TrendMicroTROJ_GEN.R002C0CLS23
SophosMal/SillyFDC-S
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/FakeAV.owle
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Fraud
KingsoftWin32.Trojan.Fraud.ezq
XcitiumTrojWare.Win32.Injector.AWLW@572uhw
MicrosoftTrojanDownloader:Win32/Beebone
ZoneAlarmTrojan.Win32.Fraud.ezq
GDataGen:Variant.Symmi.42239
VaristW32/VBKrypt.BKK.gen!Eldorado
AhnLab-V3Trojan/Win32.Beebone.R100812
McAfeeW32/Worm-AAEH.c!ABAA5FA40563
TACHYONTrojan/W32.VB-Fraud.69632
VBA32BScope.Trojan.Diple
MalwarebytesGeneric.Malware/Suspicious
PandaW32/Vobfus.GEV.worm
TrendMicro-HouseCallTROJ_GEN.R002C0CLS23
RisingDownloader.Beebone!8.2A1 (TFE:3:MkJHH6R5AjC)
YandexTrojan.Fraud!8va+QB9Q66Y
SentinelOneStatic AI – Malicious PE
FortinetW32/Refroso.AGEA!tr
AVGWin32:Downloader-VGN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.42239?

Symmi.42239 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment