Malware

Symmi.61481 removal guide

Malware Removal

The Symmi.61481 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.61481 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Arabic (Algeria)
  • Detects the presence of Wine emulator via function name
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Deletes its original binary from disk
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Symmi.61481?


File Info:

crc32: FE6A9835
md5: d0b8355fde40aa24f22a1beb819e1346
name: D0B8355FDE40AA24F22A1BEB819E1346.mlw
sha1: eb840ccf621ae181d39e236990a47d3e49ff6c98
sha256: e926c4bc9114f515e5887e19602ef32e8633e3e96155f879900e17c3958e35ca
sha512: 088b35776f180332be6cfca387f897de0aae478397a1300cb8ad4bbdb7c491364a4c78c0b352cb4eb2eafeeb4ad0bc4a85531eb9b660e3803b4a13e1cb892a10
ssdeep: 3072:JizftbeK0VBfhBU6eDLHSOOtAg0FuxZbVrbTlPaa6FIIQujMqPK7:AuBdKLyOOtAO5zlyKDB7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2007 Nero AG and its licensors
InternalName: DTShellHlp
PortableApps.comAppID: DTShellHlp
FileVersion: 4.49.1.0356
PortableApps.comFormatVersion: 2.0
CompanyName: PortableApps.com
LegalTrademarks: Copyright 2007 Nero AG and its licensors
Comments: For additional details, visit PortableApps.com
ProductName: DTShellHlp
PortableApps.comInstallerVersion: 4.49.1.0356
ProductVersion: 4.49.1.0356
FileDescription: DTShellHlp
OriginalFilename: xa9 XTreme xa9
Translation: 0x0000 0x04b0

Symmi.61481 also known as:

BkavW32.FamVT.RazyNHmC.Trojan
K7AntiVirusTrojan ( 004dfd031 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.AVKill.60062
CynetMalicious (score: 99)
CAT-QuickHealRansom.Tescrypt.A4
ALYacGen:Variant.Symmi.61481
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Lethic.673c4d49
K7GWTrojan ( 004dfd031 )
Cybereasonmalicious.fde40a
BaiduWin32.Trojan.Kryptik.abq
SymantecPacked.Generic.521
ESET-NOD32a variant of Win32/Kryptik.EPCI
APEXMalicious
AvastWin32:Dorder-W [Trj]
ClamAVWin.Ransomware.TeslaCrypt-7548519-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.61481
NANO-AntivirusTrojan.Win32.Lethic.edymyt
MicroWorld-eScanGen:Variant.Symmi.61481
TencentWin32.Trojan-proxy.Lethic.Wqmq
Ad-AwareGen:Variant.Symmi.61481
BitDefenderThetaGen:NN.ZexaF.34170.mq0@aeHMfgnO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMM1
McAfee-GW-EditionRansomware-FFK!D0B8355FDE40
FireEyeGeneric.mg.d0b8355fde40aa24
EmsisoftGen:Variant.Symmi.61481 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.rbzi
AviraHEUR/AGEN.1115795
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.197EFAB
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Lethic.N
GDataGen:Variant.Symmi.61481
AhnLab-V3Trojan/Win32.Teslacrypt.C1338561
Acronissuspicious
McAfeeRansomware-FFK!D0B8355FDE40
MAXmalware (ai score=80)
VBA32BScope.Trojan.AVKill
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMM1
RisingTrojan.Generic@ML.98 (RDML:3QulEKfkF2O/HJLLaFRMjQ)
YandexTrojan.GenAsa!tR7jHVFxw54
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EPMF!tr
AVGWin32:Dorder-W [Trj]
Paloaltogeneric.ml

How to remove Symmi.61481?

Symmi.61481 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment