Malware

How to remove “Symmi.4250”?

Malware Removal

The Symmi.4250 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.4250 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (El Salvador)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Symmi.4250?


File Info:

crc32: 207CFE8D
md5: 9690ea3f54fde810aad3c39f512841db
name: 9690EA3F54FDE810AAD3C39F512841DB.mlw
sha1: 3ade4ef99240e4aca74584af231438acfefa6a3c
sha256: 12823f46df68fa6b4fb9919327aaa1cfa3c66c8ca99743e3eb861f0141980daa
sha512: a289bbf46515c42a4222ce2131222e8a5e43e5aeb3e03d5aa30ea96f62c0c72e0d3986593781f85a8362eb80edf01af85306a5252025e4f04ad422fff9b715a1
ssdeep: 3072:2DJ+f+fqzJHRwOnt2vkdsyEPCA8InN/9HqfNGkHPv:aJ+bz1dkvkSyE6A1Np4NbX
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright JetBrains s.r.o., (c) 2000-2012
InternalName: Virtual Machine
FileVersion: 9.1.1.3.AG-111.177
CompanyName: Amphora Group
ProductName: Virtual Machine
ProductVersion: 9.1.1.3.AG-111.177
FileDescription:
OriginalFilename: myvm.exe
Translation: 0x0000 0x04b0

Symmi.4250 also known as:

K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Zbot.lEHF
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.368
CynetMalicious (score: 99)
ALYacGen:Variant.Symmi.4250
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.87044
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/EncPk.95f1c395
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.f54fde
SymantecTrojan.Shylock
ESET-NOD32Win32/Spy.Zbot.ZR
APEXMalicious
AvastWin32:Cryptor
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.4250
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.A.Zbot.180736.CW
MicroWorld-eScanGen:Variant.Symmi.4250
TencentWin32.Trojan-Spy.Zbot.cfam
Ad-AwareGen:Variant.Symmi.4250
SophosML/PE-A + Mal/EncPk-AHQ
ComodoMalware@#eca1uw1lvbl9
BitDefenderThetaGen:NN.ZexaF.34058.lG1@aqn9P!oO
VIPRETrojan.Win32.Encpk.ahq (v)
TrendMicroTROJ_RANSOM.SMWX
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.9690ea3f54fde810
EmsisoftGen:Variant.Symmi.4250 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Zbot.ckie
AviraTR/Dropper.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.12F8FF
KingsoftWin32.Troj.Zbot.(kcloud)
MicrosoftPWS:Win32/Zbot
ArcabitTrojan.Symmi.D109A
GDataGen:Variant.Symmi.4250
AhnLab-V3Spyware/Win32.Zbot.R42870
McAfeePWS-Zbot.gen.apx
MAXmalware (ai score=98)
VBA32TrojanSpy.Zbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM.SMWX
RisingTrojan.Generic@ML.100 (RDML:pElO5teEQDGSAAp533wNbA)
YandexTrojan.GenAsa!wU2nh7JHjDE
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Injector.YVD!tr
AVGWin32:Cryptor
Qihoo-360Win32/TrojanDropper.Generic.HwQAEpsA

How to remove Symmi.4250?

Symmi.4250 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment