Malware

Symmi.44378 removal instruction

Malware Removal

The Symmi.44378 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.44378 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Symmi.44378?


File Info:

name: 11AEE7E47CF08D57D5AD.mlw
path: /opt/CAPEv2/storage/binaries/c3179c85de08ce7273e74f38c41bd63ebbb2c0feac7e6399c12680f4ce9df760
crc32: 273DD316
md5: 11aee7e47cf08d57d5ada7522d588064
sha1: 54c760c95c00134b1c7b614bc49c107e639c7dcc
sha256: c3179c85de08ce7273e74f38c41bd63ebbb2c0feac7e6399c12680f4ce9df760
sha512: 35fec8b68adc7bc238d2ce4648d38dccc501414ccc20a04509320271b515c626920b7aca72e23433be2a426a7907486da22a9566ecbdaccf68644d4f5782b872
ssdeep: 12288:JLaAqsyVNFYLi7N7FTelEN1Sye1rG60Ja1y/:taH1NjJleTy560JB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1799423A4B6EE7560D295833FB5C3E40DC187B835A76009BC8A453FDD6604EC9E732267
sha3_384: 78f098f2e5d0285cf183498ff5b2248684eb4e4220d6889f071e7bc89f2a06b173fae8b9b709b352b3e409040554c1fe
ep_bytes: 558bec81ec2401000068003c50ad6a35
timestamp: 2011-06-21 21:31:46

Version Info:

CompanyName: Masnesaft Corporation
FileDescription: Masnesaft Visual Studie 2010
FileVersion: 1.9.43074.5121 built by: SP1Rel
InternalName: devenv.exe
LegalCopyright: © Masnesaft Corporation. All rights reserved.
OriginalFilename: devenv.exe
ProductName: Masnesaft® Visual Studio® 2010
ProductVersion: 1.9.43074.5121
Translation: 0x0409 0x04b0

Symmi.44378 also known as:

BkavW32.AIDetect.malware1
AVGWin32:Mystic
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.44378
FireEyeGeneric.mg.11aee7e47cf08d57
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FBTA!11AEE7E47CF0
CylanceUnsafe
VIPREGen:Variant.Symmi.44378
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Symmi.44378
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Symmi.DAD5A
BitDefenderThetaAI:Packer.6F7D508D1F
VirITTrojan.Win32.Crypt3.AFIS
CyrenW32/A-f57dfea8!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CGXH
BaiduWin32.Trojan.Kryptik.je
APEXMalicious
ClamAVWin.Trojan.Agent-1140940
KasperskyTrojan-Spy.Win32.Zbot.tohi
NANO-AntivirusTrojan.Win32.Zbot.dcjtdx
CynetMalicious (score: 100)
RisingSpyware.Zbot!8.16B (TFE:3:fNDCo6lrwMV)
Ad-AwareGen:Variant.Symmi.44378
EmsisoftGen:Variant.Symmi.44378 (B)
ComodoTrojWare.Win32.Kryptik.CHIQ@5dpgs3
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen6.15132
ZillyaTrojan.Zbot.Win32.161012
TrendMicroTSPY_ZBOT.SMRAP
McAfee-GW-EditionPWSZbot-FBTA!11AEE7E47CF0
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-AHZC
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.effo
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot.CF
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
ZoneAlarmTrojan-Spy.Win32.Zbot.tohi
GDataGen:Variant.Symmi.44378
GoogleDetected
AhnLab-V3Dropper/Win32.Necurs.R113366
Acronissuspicious
VBA32BScope.TrojanPSW.Zbot
ALYacGen:Variant.Symmi.44378
TACHYONTrojan-Spy/W32.ZBot.431169
MalwarebytesTrojan.Zbot.Gen
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SMRAP
TencentMalware.Win32.Gencirc.10c7b8e9
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.CJJL!tr
Cybereasonmalicious.47cf08
AvastWin32:Mystic

How to remove Symmi.44378?

Symmi.44378 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment