Malware

Symmi.38368 malicious file

Malware Removal

The Symmi.38368 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.38368 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Symmi.38368?


File Info:

name: 56F375A26FE8E823F65B.mlw
path: /opt/CAPEv2/storage/binaries/531ee8c4557c908ee92f58a96be1e9880f73cc79874daa17baffe3f29e63ecbb
crc32: C3BC0F1E
md5: 56f375a26fe8e823f65b8152d52bf883
sha1: d352e978497b10901a17c80699c2a08b13ae85f1
sha256: 531ee8c4557c908ee92f58a96be1e9880f73cc79874daa17baffe3f29e63ecbb
sha512: 6f50ed360a567b1cd1dd62d12b00b639f08cd8f6aaf6f5950595922f67cb85ee5d21feb429f815c4048188634739acba3cbcf8ca6c132fbd98d27548b4ce59c2
ssdeep: 6144:rR/bxfkNuX1Ed5hZ9UxhX4O498sfti2QBm1vivX:rRzx6uedXrQ4984HQB6ivX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB241224CAE39921E66643FA13343D3463B52F306F4524DB9B9E7FB496B0797040A637
sha3_384: c32dda8cc1776c957a5b9f7ed28b91ac22a9cde1d29806c8cbcc2ca5dad94b32de5906d27beb215c0dd8ac8432d4d371
ep_bytes: 000000000028ffffff6ac76a216800f8
timestamp: 2011-10-02 06:40:09

Version Info:

CompanyName: BitMefender S.R.L.
FileDescription: BitMefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: GUIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitMefender 2016
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Symmi.38368 also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
DrWebTrojan.DownLoader9.8340
MicroWorld-eScanGen:Variant.Symmi.38368
FireEyeGeneric.mg.56f375a26fe8e823
ALYacGen:Variant.Symmi.38368
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Symmi.38368
SangforSuspicious.Win32.Save.a
K7GWHacktool ( 700007861 )
Cybereasonmalicious.26fe8e
VirITTrojan.Win32.Generic.BDPN
CyrenW32/Zbot.OQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Yakes-1870
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.38368
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp
AvastWin32:Evo-gen [Trj]
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XPACK.Gen7
TrendMicroTSPY_ZBOT.SM3R
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.38368 (B)
GDataGen:Variant.Symmi.38368
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Yakes
ArcabitTrojan.Symmi.D95E0
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SM3R
RisingSpyware.Zbot!1.A1BA (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Yakes.dwzw
FortinetW32/Wacatac.B!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Symmi.38368?

Symmi.38368 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment