Malware

What is “Symmi.22748”?

Malware Removal

The Symmi.22748 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.22748 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Symmi.22748?


File Info:

name: 61890C8AC17D70A13763.mlw
path: /opt/CAPEv2/storage/binaries/a475feb44e2f6a6c23329f077d1cab9f40871fc06eb98144c29d9b4a489f53b6
crc32: D96744CB
md5: 61890c8ac17d70a1376304325ee51dbc
sha1: 75b5bd5ab08989b24a76f1240845167cfc0e9dcd
sha256: a475feb44e2f6a6c23329f077d1cab9f40871fc06eb98144c29d9b4a489f53b6
sha512: 2c28510de8783b402f60b60c7f88d34f14e1b55967e6ea8037ae4b8b9b3df87df775729a1ea3b8eede084001c1cfb6f84c6bfac3c5a7ee61e1b4fe1deb739150
ssdeep: 3072:M+fFEMwpbYkUDADbMytjVNhUYe0Tit7CMKhlCtk7Ab23O:QjpbYkYA/5tZjUYe0suUb8O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12514AE2172C884B2D587157288F4CBF60D7A7C655BA1649F3EEA3ABF6F30B91912430D
sha3_384: f41e96442c90f13e48ba2ee352d885ae83eb3087f79266121659e3a075186d8d27851fdd9a7b7048d903a223a46396cc
ep_bytes: e8e2330000e989feffff2da403000074
timestamp: 2012-10-25 06:30:07

Version Info:

CompanyName: earth
FileVersion: 6.3.687.11
FileDescription: earth Show
LegalCopyright: Copyright (C) 2006-2012
InternalName: Show
OriginalFilename: Special.exe
ProductName: earth Show
ProductVersion: 6.3.687.11
Translation: 0x0419 0x04b0

Symmi.22748 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tepfer.i!c
MicroWorld-eScanGen:Variant.Symmi.22748
FireEyeGeneric.mg.61890c8ac17d70a1
ALYacGen:Variant.Symmi.22748
Cylanceunsafe
ZillyaTrojan.Tepfer.Win32.11330
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 003f55e21 )
AlibabaTrojanPSW:Win32/Tepfer.5066b302
K7GWPassword-Stealer ( 003f55e21 )
Cybereasonmalicious.ab0898
CyrenW32/Trojan.PNSA-8381
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/PSW.Agent.NTM
APEXMalicious
ClamAVWin.Spyware.Fareit-410
KasperskyTrojan-PSW.Win32.Tepfer.bmut
BitDefenderGen:Variant.Symmi.22748
NANO-AntivirusTrojan.Win32.Stealer.bajwbd
AvastWin32:Downloader-RBS [Trj]
TencentWin32.Trojan-QQPass.QQRob.Gflw
TACHYONTrojan-PWS/W32.Tepfer.193536
SophosTroj/Mdrop-EPX
F-SecureTrojan-Downloader:W32/Agent.DUFX
DrWebTrojan.PWS.Stealer.946
VIPREGen:Variant.Symmi.22748
TrendMicroTSPY_FAREIT.NT
McAfee-GW-EditionPWS-Zbot.gen.aqj
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.22748 (B)
IkarusTrojan-PWS.Win32.Tepfer
GDataGen:Variant.Symmi.22748
JiangminTrojan/PSW.Tepfer.nix
WebrootW32.Malware.Heur
GoogleDetected
AviraHEUR/AGEN.1311793
Antiy-AVLTrojan[PSW]/Win32.Tepfer
XcitiumMalware@#zk924u5p8upd
ArcabitTrojan.Symmi.D58DC
ViRobotTrojan.Win32.A.PSW-Tepfer.193536
ZoneAlarmTrojan-PSW.Win32.Tepfer.bmut
MicrosoftPWS:Win32/Fareit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bublik.R43588
Acronissuspicious
McAfeePWS-Zbot.gen.aqj
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/OCJ.A
TrendMicro-HouseCallTSPY_FAREIT.NT
RisingMalware.FakePDF/ICON!1.9C3A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AQJ!tr
BitDefenderThetaGen:NN.ZexaF.36662.lq0@a83xQ1kc
AVGWin32:Downloader-RBS [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.22748?

Symmi.22748 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment