Malware

Should I remove “Symmi.65685”?

Malware Removal

The Symmi.65685 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.65685 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.sertanejomisturado.com.br

How to determine Symmi.65685?


File Info:

crc32: 06A64C16
md5: 5f61a894ad717b38fdad9cc6a0e98492
name: 5F61A894AD717B38FDAD9CC6A0E98492.mlw
sha1: 5050d7ae7eebc1037264dfa886ac9934e8780de6
sha256: 746cbbe6cbedea4d5f801da9b8a8e1c761c04c52d9743a3f8ed3ff24cff3eeec
sha512: e8244179f76e5d270f3e6a5a5a2554cf87666a55a057765d7acc7d23045219b7fff00b84aa9d22061c7fbbba50fe6ea20793f9dd77c13b1a4881329da255b386
ssdeep: 12288:xaWzgMg7v3qnCiMErQohh0F4CCJ8lnyfQ6NyDz+6qc3cX4nLqPHIpjup3NhYLLf:gaHMv6CorjqnyfQqyu6x3M4nL8wyhcLf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 6, 1
FileVersion: 3, 3, 6, 1
FileDescription:
Translation: 0x0809 0x04b0

Symmi.65685 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.65685
FireEyeGeneric.mg.5f61a894ad717b38
McAfeeArtemis!5F61A894AD71
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.28858
AegisLabTrojan.Win32.Autoit.4!c
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Symmi.65685
K7GWTrojan ( 700000111 )
Cybereasonmalicious.4ad717
CyrenW32/Trojan.ZCCE-5696
SymantecInfostealer.Domingo
TrendMicro-HouseCallTROJ_UTOTI.TYZAV
AvastWin32:Broban-A [Trj]
ClamAVWin.Trojan.Gamarue-6964332-0
KasperskyHEUR:Trojan.Win32.Autoit.gen
AlibabaTrojanDownloader:Win32/Banload.97d5a154
NANO-AntivirusTrojan.Win32.Autoit.czndnz
TencentWin32.Trojan.Autoit.Syrx
Ad-AwareGen:Variant.Symmi.65685
SophosTroj/AutoIt-AAV
ComodoMalware@#1k2h89vp2civy
F-SecureDropper.DR/AutoIt.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_UTOTI.TYZAV
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGen:Variant.Symmi.65685 (B)
IkarusWin32.SuspectCrc
JiangminTrojan.Autoit.iuo
WebrootW32.Trojan.GenKD
AviraDR/AutoIt.Gen
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Symmi.D10095
ZoneAlarmHEUR:Trojan.Win32.Autoit.gen
GDataGen:Variant.Symmi.65685
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.65685
VBA32Trojan.Autoit.Banker
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Banload.TNI
FortinetW32/Autoit.AAV!tr
AVGWin32:Broban-A [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Worm.AutoIt.HwoCGzEA

How to remove Symmi.65685?

Symmi.65685 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment