Threat Database Trojans Trojan.Symmy.W

Trojan.Symmy.W

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,580
Threat Level: 80 % (High)
Infected Computers: 198
First Seen: August 10, 2021
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Symmy.W on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to deceive users by disguising itself as legitimate software, making it challenging to identify and remove without proper guidance. Understanding the nature and behavior of Trojan.Symmy.W is crucial for effective removal and prevention of future infections.

What Is Trojan.Symmy.W?

Trojan.Symmy.W is identified as a Trojan-type threat, which means it is a malicious program that can cause harm to your computer system. Trojans are known for their ability to disguise themselves as useful or harmless applications, but in reality, they can lead to serious security breaches, data theft, and system compromise. The name Trojan.Symmy.W itself does not specify a known malware family, but its classification as a Trojan indicates its potential to cause significant damage.

How Trojan.Symmy.W Operates

Trojan.Symmy.W, like other Trojans, operates by exploiting vulnerabilities in the system or deceiving users into installing it willingly. Once installed, it can create backdoors for remote access, allowing attackers to control the infected system, steal sensitive information, or use the system for malicious activities such as spamming or distributing malware. The exact mechanisms of Trojan.Symmy.W may vary, but its primary goal is to compromise system security for malicious purposes.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, common symptoms may include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. Users may also notice unauthorized changes to their system settings or unexpected network activity. Since Trojan.Symmy.W is designed to be covert, some infections may not display noticeable symptoms, making regular system checks and malware scans crucial for early detection.

How to Remove Trojan.Symmy.W

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for internet access for downloading removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of Trojan.Symmy.W and other potential threats.
  3. Uninstall suspicious programs that were installed around the time the infection was detected. Be cautious and only remove programs that you do not recognize or need.
  4. Reset your browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another scan to ensure that all components of the malware have been removed and that your system is clean.

Conclusion

Removing Trojan.Symmy.W requires a thorough approach to ensure that all malicious components are eliminated from the system. By following the steps outlined above and maintaining vigilance through regular system scans and updates, users can protect their systems from future infections. It's also important to practice safe computing habits, such as avoiding suspicious downloads and emails, to prevent similar threats from compromising system security in the future.

Analysis Report

General information

Family Name: Trojan.Symmy.W
Signature status: No Signature

Known Samples

MD5: 364ab5256d7deb3b7048a923a2095ce3
SHA1: 57b825b12e0100bad5e561b386995c9079a83984
SHA256: B95948AA62C5C891CCC62E5914ED8B65226A348D0AB72A52CED51AFE9EA14172
File Size: 5.89 MB, 5887488 bytes
MD5: 716e6b6fa8d3607367c66aeca324bbfe
SHA1: e035ab8eb51df185db7c92c4f7d870523bf91306
SHA256: 9AF8381CF39FC1F6AFA0BE16DD129AEABBD07739E8F8A2174D207204534405B0
File Size: 3.88 MB, 3876352 bytes
MD5: e8bd5f1fffb94e55ca894b4c1f177c39
SHA1: 373a31f41fb16786a9dd7688c4589e25de34b53b
SHA256: 4AF5CFBF2E3C128841C9EA59D6599A642B4A2711773C5AF1F1B7B05CBAC4DCDD
File Size: 4.63 MB, 4625103 bytes
MD5: 047d974555765dd62e6fdc491c214b14
SHA1: 0bceb2f8862741dfa76f678501c5b97dda6dcc32
SHA256: DA665B4A0177BB57006C68DDC2D59778D7D12C17143F502BB1EBDB5C89C119E7
File Size: 4.68 MB, 4675584 bytes
MD5: 52e70c4e4dc82349d46a67fd3f12b627
SHA1: e13d3f7300527ade2e29787d63b9b1da9661cc29
SHA256: B20BB2DA3C2F460449EFDF4634A88DE1EA132B4F6562869A0F53BB7CD3B93558
File Size: 3.88 MB, 3877888 bytes
Show More
MD5: 67da536a3e097efc1afd71513af27a77
SHA1: 51a9402df930fe32371e7434e5658d6f850e9a69
SHA256: 2DE69B63EFE8AB3CFEB1C7374C87CC145538F4C1AAD1F0D32FB6CA88E6F294AE
File Size: 4.01 MB, 4014080 bytes
MD5: 7006f861dd4c9cfb482edfe2b433e6ab
SHA1: 992a37a390d32cd64d1dd4e899d64853d59a9153
SHA256: 33EDB1D231437F0287B15B33D604F0785971F639852DE6050A606BB4A1B1BCED
File Size: 4.70 MB, 4702208 bytes
MD5: 5fb0e1bb72d4cf2a5430a87b8927b14b
SHA1: 947afa812de315f60b4be783fd325eac4da58e85
SHA256: 2D3386D8A39C9C6C8610586B9D77FEF266FFDACC8DA1DAA6603611214B8781D3
File Size: 4.88 MB, 4884992 bytes
MD5: 40f60c2256249e01395f280f0f83eba3
SHA1: 316d5c2cac230fe460b9a90f0b10b20e93636871
SHA256: A3DA5E7BF3BCE86482669184CF71DD65CE7C964105ACF13BE2B2DE7E1EB49ED9
File Size: 4.68 MB, 4675584 bytes
MD5: ab8806e7719c4fcae4f519439e52346e
SHA1: 86c396c6da6efdcaac86ee6359a6e60eae035689
SHA256: 067F9C7B4CB3D7D442E16350B3458D98040D0BC85B4331FD688B0B88B5371906
File Size: 1.96 MB, 1956864 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Created by VagLogins corporation
  • This installation was built with Inno Setup.
Company Name
  • Drobinski Maciej StrongRecovery
  • Microsoft
  • Synaptics
File Description
  • StrongRecovery Setup
  • Synaptics Pointing Device Driver
File Version
  • 4.6.4.1
  • 1.1.33.00
  • 1.00
  • 1.0.0.4
  • 1.0.0.0
Internal Name Win
Original Filename Win.exe
Product Name
  • StrongRecovery
  • Synaptics Pointing Device Driver
  • Win
Product Version
  • 4.6.4.1
  • 1.1.33.00
  • 1.00
  • 1.0.0.0

Digital Signatures

Signer Root Status
trust_45e5d4a0-d89e-412a-bf22-a6daa1091fad trust_45e5d4a0-d89e-412a-bf22-a6daa1091fad Self Signed

File Traits

  • 2+ executable sections
  • AutoHK
  • dll
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 4
Potentially Malicious Blocks: 1
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxac67.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\rcxbc60.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\rcxfa44.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\aj7w4jo.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\qib11cw.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
Show More
c:\users\user\appdata\roaming\winsl\l1\8\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl\l5\5\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_0bceb2f8862741dfa76f678501c5b97dda6dcc32_0004675584 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_0bceb2f8862741dfa76f678501c5b97dda6dcc32_0004675584 Synchronize,Write Attributes
c:\users\user\downloads\._cache_316d5c2cac230fe460b9a90f0b10b20e93636871_0004675584 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_316d5c2cac230fe460b9a90f0b10b20e93636871_0004675584 Synchronize,Write Attributes
c:\users\user\downloads\._cache_992a37a390d32cd64d1dd4e899d64853d59a9153_0004702208 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_992a37a390d32cd64d1dd4e899d64853d59a9153_0004702208 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0k8��8tXz��B�8 �6 �v z 5� �Z xy ��T���B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1k 8��8tXz��B�8 �6 �v z 5� �Z xy ��T���B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��7 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee*Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2k 8��8tXz��B�8 �6 �v z 5� �Z xy ����T���B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 3k8��8tXz��B�8 �6 �v z 5� �Z xy ����T���B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p ��^�o�ee>Vs}kP~��1.��7 ���ﺃee��� ��1'��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-�b�jYҴB�t�� �S� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Ul �v������Bx(�1`1�1HO@V�H[uN$k`k�q�P���!���� ���3������m���V�$�8���V�l��&M�~B1_`�V������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Vl �v������Bx(�1`1�1HO@V�H[uN$k`k�qw�n�P���!���� ���3������m���V�$�8���V�l��&M�~B1_`�V������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Wl  �v������Bx(�1`1�1HO@V�H[uN$k`k�qw�n�P���!���� ���3��������m���V�$�8���V�l��&M�~B1_`�V������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陋ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Xl& �v��������Bx(�1`1�1HO@V�H[uN$k`k�qw�n�P���!�����7� ���3�M��������m���IV�V�$�8���V�l��&M�(!��j�~�B1_`�V������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Yl' �v��������Bx(�1`1�1HO@V�H[uN$k`k�qr�7w�n�P���!�����7� ���3�M��������m���IV�V�$�8���V�l��&M�(!��j�~�B1_`�V������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Zl' �v��������Bx(�1`1�1HO@V�H[uN$k`k�qr�7w�n�P���!�����7� ���3�M��������m���IV�V�$�8���V�l��&M�(!��j �~�B1_`�V�R�������Q]��@K�A*�"C��| RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Service Control
  • OpenSCManager
Process Shell Execute
  • ShellExecuteEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • socket

Shell Command Execution

runas c:\users\user\downloads\._cache_0bceb2f8862741dfa76f678501c5b97dda6dcc32_0004675584
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate
runas c:\users\user\downloads\._cache_992a37a390d32cd64d1dd4e899d64853d59a9153_0004702208
runas c:\users\user\downloads\._cache_316d5c2cac230fe460b9a90f0b10b20e93636871_0004675584

Trending

Most Viewed

Loading...