Malware

Symmi.9639 (B) malicious file

Malware Removal

The Symmi.9639 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.9639 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Symmi.9639 (B)?


File Info:

name: 926C21DE01209B0CFC9F.mlw
path: /opt/CAPEv2/storage/binaries/96fbd25422396ec3dd5f6e4b64ecceae14e86ac0a6c73056fe5e036fb282082a
crc32: 3257AD6F
md5: 926c21de01209b0cfc9f67843e057a56
sha1: 765c466e04d21909f7836497e002399f136e3a7f
sha256: 96fbd25422396ec3dd5f6e4b64ecceae14e86ac0a6c73056fe5e036fb282082a
sha512: 672dfe14cf1331d9589b53aa9d1ea006fd7689aefea1fa56015395f8b93ab2807ff061d9a2f5030c08d248781a6f9cc2c6a42269f17d24a3c80f6bab057859b6
ssdeep: 3072:P9bEcvp0N5BdKxmSI7Dc/19h83AiPa2fWwkWlKYRNYqXbChk4QFrQuyNRSRB:1D0SxmH4/19S3AiScWnWlKYRNhbkyFU2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5E3942A76D0F23AC426CBF5392A87A4906DBC752196A903F7C10F1577F5EAB9321703
sha3_384: 8b471f976748d4297b255fa498d7110c02c0099f556821822fed79d442322cd8ebb713a9af3ae924ea3ae836247304fd
ep_bytes: 686c3b4000e8f0ffffff000058000000
timestamp: 2011-08-19 14:10:49

Version Info:

Translation: 0x0409 0x04b0
ProductName: tTSeTDPW
FileVersion: 1.00
ProductVersion: 1.00
InternalName: hyXJynuTVeEtMT
OriginalFilename: hyXJynuTVeEtMT.exe

Symmi.9639 (B) also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.o!c
MicroWorld-eScanGen:Variant.Symmi.9639
FireEyeGeneric.mg.926c21de01209b0c
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.aq
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff613.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e01209
BitDefenderThetaAI:Packer.6A76F32420
VirITTrojan.Win32.VB.BMLT
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.OBU
APEXMalicious
AvastWin32:VB-XMY [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
BitDefenderGen:Variant.Symmi.9639
NANO-AntivirusTrojan.Win32.VBKrypt.cmxsdh
TencentWorm.Win32.Vobfus.ku
EmsisoftGen:Variant.Symmi.9639 (B)
BaiduWin32.Worm.Pronny.d
F-SecureWorm.WORM/Vobfus.aba
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Symmi.9639
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-P
IkarusGen.Trojan.Heur
MAXmalware (ai score=80)
GoogleDetected
AviraWORM/Vobfus.aba
VaristW32/Vobfus.P.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.Vobfuscated.abu@4mtrya
ArcabitTrojan.Symmi.D25A7
ViRobotTrojan.Win32.A.VBKrypt.155648.D
ZoneAlarmWorm.Win32.Vobfus.exgu
GDataWin32.Trojan.PSE.10I69CR
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R121529
Acronissuspicious
VBA32Trojan.VBRA.019970
ALYacGen:Variant.Symmi.9639
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99E0 (CLASSIC)
YandexTrojan.GenAsa!efJuOH/PjIU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.G!tr
AVGWin32:VB-XMY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.bb053d49

How to remove Symmi.9639 (B)?

Symmi.9639 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment