Malware

Should I remove “Symmi.28558”?

Malware Removal

The Symmi.28558 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.28558 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Symmi.28558?


File Info:

name: C111A0B511C4EB8862A9.mlw
path: /opt/CAPEv2/storage/binaries/744bdde75770cc26fbf71f174212c54979f182ff4edeb980b6220ea7d976c459
crc32: 503E6BAF
md5: c111a0b511c4eb8862a9fe6c8f703324
sha1: be852a8e52832fa1b3066a787a50e1f556417d46
sha256: 744bdde75770cc26fbf71f174212c54979f182ff4edeb980b6220ea7d976c459
sha512: b24ca9ec156d87c9c4c78598b10c4f74913a594dd8fa8942ccfafb4b01a182daa214ccdeb5f953bbb0c53ffe0cd08e099597bb286eaabac3d2a1339187762298
ssdeep: 12288:BToHXhoFajXLV6y9wUW9uKNHxnTZhujV9POwh7jqvRCpyo7:BToHXhfj4Gwn9PNRVEJNPqvUyo7
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T188559E12B991C4F1D24D26345566B73EBA75BE458A30CAC3F3D4FEAB3C32281563621E
sha3_384: 5d43b4889204cd812a63b8fe79bb417718fca0aafc8595e92c5d235c37a10ed25559703c5282fe1290738e91c979626e
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-04-16 04:09:54

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Symmi.28558 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIa2
ElasticWindows.Generic.Threat
MicroWorld-eScanGen:Variant.Symmi.28558
CAT-QuickHealRiskTool.FlyStudio.1984
SkyhighBehavesLike.Win32.Generic.tm
McAfeeGeneric.gn
Cylanceunsafe
VIPREGen:Variant.Symmi.28558
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 000174511 )
AlibabaRiskWare:Win32/FlyStudio.1e922c30
K7GWPassword-Stealer ( 000174511 )
BaiduWin32.Trojan-PSW.OLGames.an
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0PC424
Paloaltogeneric.ml
ClamAVWin.Dropper.Detected-10008752-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.28558
AvastWin32:Malware-gen
EmsisoftGen:Variant.Symmi.28558 (B)
GoogleDetected
ZillyaTrojan.Generic.Win32.1865372
TrendMicroTROJ_GEN.R002C0PC424
FireEyeGeneric.mg.c111a0b511c4eb88
SophosTroj/Agent-BDTR
SentinelOneStatic AI – Malicious PE
VaristW32/OnlineGames.HH.gen!Eldorado
MAXmalware (ai score=84)
Antiy-AVLRiskWare/Win32.FlyStudio.a
Kingsoftmalware.kb.a.993
MicrosoftTrojan:Win32/Wacatac.A!ml
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Symmi.D6F8E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.FlyStudio.I
CynetMalicious (score: 100)
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Symmi.28558
MalwarebytesGeneric.Malware.AI.DDS
RisingMalware.Undefined!8.C (TFE:5:vhsfBryYydT)
IkarusTrojan-PSW.QQTen
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/QQTen
BitDefenderThetaGen:NN.ZedlaF.36804.rv8@aefdLBnb
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Symmi

How to remove Symmi.28558?

Symmi.28558 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment