Malware

Symmi.4923 removal guide

Malware Removal

The Symmi.4923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.4923 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Symmi.4923?


File Info:

name: 9E7591FF0D8597292954.mlw
path: /opt/CAPEv2/storage/binaries/3d0e6ecd1a738422e948613334b85e806463e1c5e8b21cf81bb7674c21bafab3
crc32: 9F48C101
md5: 9e7591ff0d85972929545b778cd26e1d
sha1: 22c585fa6298d1853337ad48a178917610f6bea4
sha256: 3d0e6ecd1a738422e948613334b85e806463e1c5e8b21cf81bb7674c21bafab3
sha512: 0dd7f5b16b4df2b05a5e097c822b0c54f75a881c04fcc8b538aa088d658521c9c6791f2688653b32c6e73fe39fffb51f7320ea71ece8ad513d6615681d873e6b
ssdeep: 768:vAV68qOJ+TtLyPwHpFeh6gM1rA8dOsc7jUq4RkA5o3K1DfsvtzsXjLft+9o1mm:vAVHqlZ24LFjnAzA5o6BfItoXjLl0hm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E293C63FBB169881E55CA27416F6CBF516FB7C57270B100BA74037AA28E6E041DACD93
sha3_384: 72c2504bcfb2d24c412a8bee87c4bc34f1e8d62356df6818f543f127dd5d2ce3749897e69e4d84df95876660a0597fc6
ep_bytes: 6828124000e8f0ffffff000000000000
timestamp: 2012-09-14 05:23:58

Version Info:

Translation: 0x0409 0x04b0
ProductName: acopon
FileVersion: 2.69
ProductVersion: 2.69
InternalName: topsailite
OriginalFilename: topsailite.exe

Symmi.4923 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.tsjm
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.25776
MicroWorld-eScanGen:Variant.Symmi.4923
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.9e7591ff0d859729
CAT-QuickHealTrojan.Beebone.D
McAfeeGenDownloader.rv
MalwarebytesPronny.Worm.Spreader.DDS
VIPREGen:Variant.Symmi.4923
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2f92.None
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36250.fm0@a0r3F3pi
VirITWorm.Win32.X-Autorun.BMDK
CyrenW32/Vobfus.AT.gen!Eldorado
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Pronny.BJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dhlj
BitDefenderGen:Variant.Symmi.4923
NANO-AntivirusTrojan.Win32.Autoruner1.jvjuka
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEMB [Trj]
TencentWorm.Win32.Vobfus.ha
EmsisoftGen:Variant.Symmi.4923 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaWorm.Vobfus.Win32.1192592
TrendMicroWORM_VOBFUS.SM02
McAfee-GW-EditionBehavesLike.Win32.VBObfus.mm
Trapminemalicious.high.ml.score
SophosMal/BeeBone-AE
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.4923
JiangminTrojan/Vbobf.b
WebrootW32.Trojan.Agent.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.EB@4qtzpj
ArcabitTrojan.Symmi.D133B
ZoneAlarmWorm.Win32.Vobfus.dhlj
MicrosoftWorm:Win32/Vobfus.HU
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R36560
ALYacGen:Variant.Symmi.4923
TACHYONTrojan/W32.Agent.90112
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!6+Gc6qr5vwQ
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.5486835.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AEMB [Trj]
Cybereasonmalicious.f0d859
DeepInstinctMALICIOUS

How to remove Symmi.4923?

Symmi.4923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment