Malware

Symmi.93136 removal instruction

Malware Removal

The Symmi.93136 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.93136 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings

How to determine Symmi.93136?


File Info:

name: 501678D55584F599FC16.mlw
path: /opt/CAPEv2/storage/binaries/4f26a9eb064d7155ecb022937cef80276c420b02b0ee55e6a5e7345a31e4ee06
crc32: 09F5A5FE
md5: 501678d55584f599fc168a21f4b30d2d
sha1: 42a044d75a9c857ac80eb002310597c981d51e06
sha256: 4f26a9eb064d7155ecb022937cef80276c420b02b0ee55e6a5e7345a31e4ee06
sha512: 8ef4f20a4da3c2131aa833f5b25bb7684fb4c7e448d1293c0f5ba6f5401ce1456786d4dfe53a24459dfd2fe9062a5a9bdfa316599ba2f5ab9c6099403df1cf95
ssdeep: 1536:NSHcWgnQs8VMNvY3vy3QpTha55R8VQ2oLmh:N0cIs8mNvY63Qhha556oLmh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144245C20E341C03AECD141FED1AA8BB6BD255E706B98A4E7C3D0B4DDD76A1E17A3414B
sha3_384: 52259b9c6fa70825516b468d440da121d5aa885f9a95a962eac4c83c9ae67851453e84823f2011b55607908e32bea02c
ep_bytes: 558bec6aff68e078420068f492400064
timestamp: 2012-09-27 13:10:11

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Symmi.93136 also known as:

BkavW32.FamVT.MyDoomTY.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.23869
MicroWorld-eScanGen:Variant.Symmi.93136
FireEyeGeneric.mg.501678d55584f599
CAT-QuickHealWorm.Ganelp.A6
ALYacGen:Variant.Symmi.93136
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1102281
K7AntiVirusTrojan ( 001f4ea51 )
K7GWTrojan ( 001f4ea51 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34294.my2@ayGGPhmG
CyrenW32/Agent.KI.gen!Eldorado
SymantecW32.Griptolo
ESET-NOD32a variant of Win32/Agent.SRG
TrendMicro-HouseCallWORM_GANELP.SMIA
ClamAVWin.Trojan.BankerSpy-1
KasperskyWorm.Win32.Juched.fgq
BitDefenderGen:Variant.Symmi.93136
NANO-AntivirusTrojan.Win32.Juched.fiiwse
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
AvastWin32:Agent-APNJ [Trj]
RisingTrojan.Agent!1.C135 (CLASSIC)
Ad-AwareGen:Variant.Symmi.93136
SophosML/PE-A + Troj/Juched-A
ComodoWorm.Win32.Juched.PGY@4yojo0
BaiduWin32.Trojan.Agent.dc
TrendMicroWORM_GANELP.SMIA
McAfee-GW-EditionBehavesLike.Win32.Autorun.dz
EmsisoftGen:Variant.Symmi.93136 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.13GI8NU
JiangminWorm/Generic.abnf
AviraTR/Crypt.ZPACK.Gen7
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.12C32B
MicrosoftWorm:Win32/Ganelp.gen!A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Npkon.C195491
Acronissuspicious
McAfeeW32/Worm-FBL!501678D55584
VBA32Worm.Juched
MalwarebytesBackdoor.IRCBot
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
IkarusTrojan.Win32.Webprefix
MaxSecureWorm.Win32.Juched.FIH
FortinetW32/Agent.SRG!tr
AVGWin32:Agent-APNJ [Trj]
Cybereasonmalicious.55584f
PandaTrj/Genetic.gen

How to remove Symmi.93136?

Symmi.93136 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment