Malware

Symmi.6261 (B) removal tips

Malware Removal

The Symmi.6261 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.6261 (B) virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.spansearcher.net

How to determine Symmi.6261 (B)?


File Info:

crc32: DA3837B4
md5: 1278f73d17f8123920a5012d10447608
name: 1278F73D17F8123920A5012D10447608.mlw
sha1: 44628556c918f7a9610909342e53ff4ffd4c2e04
sha256: 1d393a4401f427b56adf5e8bcfd262aa9f851270f8a869ea3efc3389dcea66a8
sha512: 5f7ee7b681cb9053bee1bd539d32e6a4f6dc42f537ef00fcb3fda7ae329e419e9aa948f260ec877a2fc0f0f69b54744fb82b88c74576afc725eaa61f6be3b7d4
ssdeep: 3072:1C1To/0YxkA0tQ9nLHbB9WPliBs2HWWEakGJm9Bo:1CoV4QxL7B9WPli+yWWEazi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 7.08.0002
InternalName: phxjiegzhb
FileVersion: 7.08.0002
OriginalFilename: phxjiegzhb.exe
ProductName: hkdbhlxw

Symmi.6261 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.6261
FireEyeGeneric.mg.1278f73d17f81239
CAT-QuickHealTrojan.Beebone.D
Qihoo-360Worm.Win32.VB.T
ALYacGen:Variant.Symmi.6261
MalwarebytesVobfus.Worm.Evasion.DDS
VIPRETrojan.Win32.Vobfus.a (v)
SangforMalware
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Symmi.6261
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.d17f81
BaiduWin32.Worm.Pronny.h
CyrenW32/Vobfus.J.gen!Eldorado
SymantecW32.Changeup
TotalDefenseWin32/Vobfus.AFO
TrendMicro-HouseCallWORM_VOBFUS.SME
Paloaltogeneric.ml
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bdmh
AlibabaWorm:Win32/VBInject.e7d4ea0f
NANO-AntivirusTrojan.Win32.VB.cqkxpf
ViRobotTrojan.Win32.VB.204800.H
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
TencentTrojan.Win32.VB.tsw
Ad-AwareGen:Variant.Symmi.6261
SophosML/PE-A + Mal/VBCheMan-G
ComodoWorm.Win32.Pronny.AK@4ogvoo
F-SecureTrojan.TR/VB.Inject.11591
DrWebWin32.HLLW.Autoruner1.15026
TrendMicroWORM_VOBFUS.SME
McAfee-GW-EditionBehavesLike.Win32.Downloader.dm
EmsisoftGen:Variant.Symmi.6261 (B)
IkarusTrojan.Patched
GDataGen:Variant.Symmi.6261
JiangminWorm/VBNA.gybw
AviraTR/VB.Inject.11591
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Symmi.D1875
AegisLabWorm.Win32.WBNA.kZq0
ZoneAlarmWorm.Win32.VBNA.bdmh
MicrosoftVirTool:Win32/VBInject.WX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R40142
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Agent.237568.CB
VBA32SScope.Malware-Cryptor.VBCR.3042
CylanceUnsafe
PandaGeneric Malware
APEXMalicious
ESET-NOD32Win32/Pronny.AI
RisingWorm.VobfusEx!1.99DC (CLOUD)
YandexTrojan.GenAsa!KnbUZ/Nfsmk
SentinelOneStatic AI – Malicious PE – Worm
eGambitUnsafe.AI_Score_100%
FortinetW32/Jorik.EGLG!tr
BitDefenderThetaGen:NN.ZevbaF.34804.oq0@aafaimpi
AVGWin32:VB-ACNQ [Trj]
AvastWin32:VB-ACNQ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureWorm.W32.VBNA.bdmh

How to remove Symmi.6261 (B)?

Symmi.6261 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment