Malware

Should I remove “Symmi.6017 (B)”?

Malware Removal

The Symmi.6017 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.6017 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Symmi.6017 (B)?


File Info:

name: D5A928786D40935A05E1.mlw
path: /opt/CAPEv2/storage/binaries/b2dd3ad8237ac6e5de1bee23b028914feee2fb416175bc7569edd841b95c3a2f
crc32: 8DFD39E1
md5: d5a928786d40935a05e1d7cb0383edce
sha1: b241cebe005fc9b8e03e6ddc94accce7078374d2
sha256: b2dd3ad8237ac6e5de1bee23b028914feee2fb416175bc7569edd841b95c3a2f
sha512: 6104629e3e67a1a567c128a2c0d00f7a81149ce1fc747f298e7a492e7b0cc781b992ca6578b68f631acccf1ba639504baf12c23592192df91e22f65fa520e249
ssdeep: 3072:2k6kvZjWnE5lIqaAF/OVLj4UbaxxmLQTi2//9U33T+NVzo:21kBmAHaAF4RFSs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11624073EBB921559D668493226D6C3F11773740E8F7B808FAA482B6A3CB1E340D2D757
sha3_384: b7d9b8b13118159426697017618436e56617c8fa83633db8b1fbe1307ce5a7ad5e17fdcbd25fb1f65c63a8a996121577
ep_bytes: 6858154000e8f0ffffff000058000000
timestamp: 2012-08-17 05:30:31

Version Info:

Translation: 0x0409 0x04b0
Comments: Accomodare Lordotic Fratturino
CompanyName: Accomodare Lordotic Fratturino
FileDescription: Accomodare Lordotic Fratturino
LegalCopyright: Accomodare Lordotic Fratturino
LegalTrademarks: Accomodare Lordotic Fratturino
ProductName: Accomodare Lordotic Fratturino
FileVersion: 8.86
ProductVersion: 8.86
InternalName: dinamode
OriginalFilename: dinamode.exe

Symmi.6017 (B) also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.lJgU
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.6017
FireEyeGeneric.mg.d5a928786d40935a
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.ek
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1522301
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.fc471d08
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BitDefenderThetaGen:NN.ZevbaF.36804.om0@ayZOvRci
VirITTrojan.Win32.Generic.ZBH
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AYI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Worm.Vobus-10005312-1
KasperskyWorm.Win32.Vobfus.amsv
BitDefenderGen:Variant.Symmi.6017
NANO-AntivirusTrojan.Win32.Vobfus.covjwt
AvastWin32:VB-AEDI [Trj]
TencentWorm.Win32.Vobfus.m
TACHYONTrojan/W32.Agent.229376
SophosMal/Kovter-W
BaiduWin32.Worm.VB.nm
F-SecureTrojan.TR/Zusy.16475
DrWebWin32.HLLW.Autoruner1.25059
VIPREGen:Variant.Symmi.6017
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.6017 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.UDY479
JiangminTrojan/Jorik.gssf
WebrootW32.Obfuscated.Gen
VaristW32/VB.HA.gen!Eldorado
AviraTR/Zusy.16475
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Symmi.D1781
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.Vobfus.amsv
MicrosoftWorm:Win32/Vobfus.GY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R33547
ALYacGen:Variant.Symmi.6017
GoogleDetected
MAXmalware (ai score=100)
VBA32Trojan.Vobfus
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!hL/+VllelXs
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Malware.11602031.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEDI [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.a8ca13a1

How to remove Symmi.6017 (B)?

Symmi.6017 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment