Malware

Symmi.88951 removal guide

Malware Removal

The Symmi.88951 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.88951 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Accessed credential storage registry keys
  • Anomalous binary characteristics

How to determine Symmi.88951?


File Info:

name: A773A00A06C940E1A5AF.mlw
path: /opt/CAPEv2/storage/binaries/22d03548dc9b851944a08101e2dd9c6d9135d3f615f84f7d006291f33159d9f4
crc32: 464154BB
md5: a773a00a06c940e1a5afe64e4b80ac5e
sha1: 9881b91c249efecfe858a889000a6fe2a427f522
sha256: 22d03548dc9b851944a08101e2dd9c6d9135d3f615f84f7d006291f33159d9f4
sha512: 9bfc65c4156b0baebfafefe590ad8fefac9ae500677bdae8f0605ef6c3a618e84d121d408a00eb7234aab3d8f22df134f56378cdf5a598f17aa49b111b3e649a
ssdeep: 49152:nQV0TnRT9iak21sNA+Xk7SYwAT6vcO4z8AQD3lua:40TnRT9Lt1YA+LA2vcOBAQ3R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CD58E4AF608CF16C0595233880FDE5A4625BEE55E02A80773CC7BBE2F727A56EC065D
sha3_384: 1209d99269a5b7d76cc7cf9dd76d45c21eda9565ff890c67d5ca7a924f9b16cd2596cf4e65503e3f6ecceace024115cf
ep_bytes: 558bec6aff6870934e0068d4404e0064
timestamp: 2018-11-15 14:48:30

Version Info:

CompanyName: NODJE
FileVersion: 10.2.1.2349
ProductName: NODJE Internet Security
ProductVersion: 10.2.1.2349
Translation: 0x0409 0x04e4

Symmi.88951 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3825
MicroWorld-eScanGen:Variant.Symmi.88951
FireEyeGeneric.mg.a773a00a06c940e1
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePacked-FME!A773A00A06C9
CylanceUnsafe
ZillyaTrojan.Generic.Win32.380367
K7AntiVirusTrojan ( 0053e8521 )
AlibabaTrojan:Win32/Ekstak.69418c1d
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.a06c94
BitDefenderThetaGen:NN.ZexaF.34294.Xs0@aayJ9qei
CyrenW32/Ekstak.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMTI
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.88951
NANO-AntivirusTrojan.Win32.Ekstak.fkfncz
AvastWin32:ICLoader-X [Adw]
TencentMalware.Win32.Gencirc.10cd34b8
Ad-AwareGen:Variant.Symmi.88951
EmsisoftGen:Variant.Symmi.88951 (B)
ComodoApplication.Win32.ICLoader.GS@84429a
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosMal/Generic-S
IkarusPUA.Generic
GDataGen:Variant.Symmi.88951
JiangminTrojan.Generic.cvbnd
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.295CDAB
ArcabitTrojan.Symmi.D15B77
MicrosoftSoftwareBundler:Win32/ICLoader
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.ICLoader.R244932
Acronissuspicious
VBA32BScope.Trojan.Moneyinst
ALYacGen:Variant.Symmi.88951
MAXmalware (ai score=81)
MalwarebytesTrojan.Downloader
APEXMalicious
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!M6J3RmwYlc8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
PandaTrj/Genetic.gen

How to remove Symmi.88951?

Symmi.88951 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment