Malware

Should I remove “Symmi.67014”?

Malware Removal

The Symmi.67014 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.67014 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Symmi.67014?


File Info:

crc32: 7F7AB88B
md5: 9b5d6582e4769414e13ab215235e3723
name: 9B5D6582E4769414E13AB215235E3723.mlw
sha1: b40b86f50bcc99fcf5ebfe1a3e3f982230975771
sha256: fa2c5f9d5c0000ccc8d3c3e9f752dbe22cbd48f0ce8945d36c0b40988b73746c
sha512: 9f8dd2fd75e2a50b37e96335bd0394313a6b1269588553ded2ad3e1f4613929d12b0faca126818910bd28f4258a19bf3f77c0e55c82b2327b2139f93c80f0259
ssdeep: 3072:q3L001Vk0ozxAyjZmwWlZDcvedvsvNKzbk7LDpLFHxMj9V0F:qV1Vkc3PvsvNKzw7nZBxU9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Dynip2
FileVersion: 1.01.0001
CompanyName: "CJSC "Computing Forces"
Comments: Antiputrid
ProductName: Paramyotone
ProductVersion: 1.01.0001
FileDescription: Morra
OriginalFilename: Dynip2.exe

Symmi.67014 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004db1d21 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.67014
CylanceUnsafe
ZillyaTrojan.Injector.Win32.357562
SangforSuspicious.Win32.Save.a
AlibabaTrojanPSW:Win32/Injector.e661f028
K7GWTrojan ( 004db1d21 )
Cybereasonmalicious.2e4769
CyrenW32/Trojan.XCSE-2585
SymantecInfostealer.Limitail
ESET-NOD32a variant of Win32/Injector.CPON
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.Win32.Fareit.dhog
BitDefenderGen:Variant.Symmi.67014
NANO-AntivirusTrojan.Win32.Inject.dzpiii
ViRobotTrojan.Win32.S.Zbot.204800.AP
MicroWorld-eScanGen:Variant.Symmi.67014
TencentWin32.Trojan-qqpass.Qqrob.Hupp
Ad-AwareGen:Variant.Symmi.67014
SophosML/PE-A + Troj/Fareit-ZR
BitDefenderThetaGen:NN.ZevbaF.34236.mm0@aCp34xfi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.YUYAMM
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FireEyeGeneric.mg.9b5d6582e4769414
EmsisoftGen:Variant.Symmi.67014 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112829
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1A36BE3
MicrosoftVirTool:Win32/Injector.FQ
GDataGen:Variant.Symmi.67014
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeVawtrak-FBA!9B5D6582E476
MAXmalware (ai score=83)
VBA32BScope.TrojanSpy.BitWall
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_ZBOT.YUYAMM
YandexTrojan.Injector!rclUIRn46LE
IkarusTrojan-PSW.Fareit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CPGG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Symmi.67014?

Symmi.67014 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment