Malware

About “Symmi.4579” infection

Malware Removal

The Symmi.4579 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.4579 virus can do?

  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering

How to determine Symmi.4579?


File Info:

name: 1D071EC85518B86FCD99.mlw
path: /opt/CAPEv2/storage/binaries/b40b13d09be7ed34c41648166a50d1cad6692798f290278d282c32131aec05bc
crc32: 6CD0C238
md5: 1d071ec85518b86fcd99bda4e33bb6ec
sha1: 1431d111279569f69a17f3ccbf2aaf0befc7a643
sha256: b40b13d09be7ed34c41648166a50d1cad6692798f290278d282c32131aec05bc
sha512: 95a5a376e563d94c7acc03c8e522b293a5002e083f35d593da7595b486df9c9a40b0ff414c766d90fff0eaea0341fc5b9afc51956ac9f4a12073a0c480856635
ssdeep: 1536:L5iBob+w76Mj+wpw7/BUctSqIOevWFODz8OKh1YjNvDaPLABapUL0AGeujS97VqT:vbDi5UctznIHnK8ZLo7UYAGW9o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169D3E0227451D072D22941B80416CB95AF7B9C301AF1AA8777BE7E4EBC363E59D2B30D
sha3_384: 3bf93f8a7987fe1dd306cd9d3cf271330e33a7ca0d92bd2b0e309fe77e5f71a5b50a681add7386c02aa7adcbb59896b0
ep_bytes: e8be1d0000e917feffff558bec515153
timestamp: 2012-09-13 12:19:28

Version Info:

0: [No Data]

Symmi.4579 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buterat.lCWh
AVGWin32:Buterat-RB [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.4579
FireEyeGeneric.mg.1d071ec85518b86f
CAT-QuickHealTrojan.Vundo.Gen
McAfeeGeneric BackDoor.acz
Cylanceunsafe
ZillyaTrojan.SpyVoltar.Win32.65
SangforTrojan.Win32.Save.a
AlibabaVirTool:Win32/Injector.c5f2d05a
K7GWSpyware ( 002edad51 )
K7AntiVirusSpyware ( 002edad51 )
BitDefenderThetaAI:Packer.E3D5EFB121
VirITTrojan.Win32.Generic.BCLR
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:Buterat-RB [Trj]
ClamAVWin.Trojan.17973-3
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.4579
NANO-AntivirusTrojan.Win32.Jorik.bblsmn
TACHYONTrojan/W32.Jorik.135168.X
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebBackDoor.Butirat.91
VIPREGen:Variant.Symmi.4579
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Symmi.4579 (B)
JiangminTrojan/PornoAsset.cyr
WebrootW32.Jorik.Buterat
VaristW32/Zbot.EW.gen!Eldorado
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Buterat
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Vundo.QA
XcitiumTrojWare.Win32.Buterat.WDX@4r7wue
ArcabitTrojan.Symmi.D11E3
ViRobotTrojan.Win32.A.PornoAsset.135168.E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.4579
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R33217
VBA32Hoax.PornoAsset
ALYacGen:Variant.Symmi.4579
MAXmalware (ai score=99)
MalwarebytesMalware.AI.965437211
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_BUTERAT_BK2228EE.TOMC
TencentMalware.Win32.Gencirc.10b43eb3
YandexTrojan.GenAsa!9ZDgEmTr/Aw
IkarusBackdoor.Win32.Buterat
MaxSecureTrojan.Malware.4527298.susgen
FortinetW32/Kryptik.GOGY!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/SpyVoltar.A

How to remove Symmi.4579?

Symmi.4579 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment