Malware

How to remove “Symmi.44825”?

Malware Removal

The Symmi.44825 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.44825 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Symmi.44825?


File Info:

name: 0FDDB24D4666E517214E.mlw
path: /opt/CAPEv2/storage/binaries/e7fc137916d713e77cf6c748e456ade4d669c18059e714e630a43332ef4a9545
crc32: A334012C
md5: 0fddb24d4666e517214ec980015b3c60
sha1: edcd2c21e256e702c9ea7fc4e7811f671cdf7677
sha256: e7fc137916d713e77cf6c748e456ade4d669c18059e714e630a43332ef4a9545
sha512: 6b656d8e4287a53aa1cded2a0734bb8b4574467a90e351e01f68171a24ddfdfbf988e8fcff760f0a826d33007c02afc9bf241eb0e147637e8c74980264b6712b
ssdeep: 6144:gYcaYqqO/3ohJ7GNgV3ykicxXzBWE5KWg+wrXvyjvh3pwLJbjgR8D:gna1XwhJ7L7ie8TjbvyjvhylQR8D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E742320CE816475EDF667FF9C82A6330463B4519130422B694E29DDAF235959BBF20F
sha3_384: 860c986ede0cd76e915d93afb0d73e9ce4f0f165d47a90e62f0fb43f11e4ac4fde105a37e995666154cd3de2c0d4c603
ep_bytes: 558bec81ecdc0000008b0d54c0430089
timestamp: 2012-09-08 07:44:39

Version Info:

CompanyName: Masresaft Corporation
FileDescription: Masresaft Visual Studio 2010
FileVersion: 1.9.43074.5121 built by: SP1Rel
InternalName: devenv.exe
LegalCopyright: © Masresaft Corporation. All rights reserved.
OriginalFilename: devenv.exe
ProductName: Masresaft® Visual Studio® 2010
ProductVersion: 1.9.43074.5121
Translation: 0x0409 0x04b0

Symmi.44825 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.44825
ClamAVWin.Trojan.Zbot-59348
FireEyeGeneric.mg.0fddb24d4666e517
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FBTA!0FDDB24D4666
MalwarebytesTrojan.Zbot.Gen
VIPREGen:Variant.Symmi.44825
SangforTrojan.Win32.Kryptik.CGBS
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.d4666e
BaiduWin32.Trojan.Kryptik.je
VirITTrojan.Win32.Crypt3.ADEH
CyrenW32/A-8c1f9c73!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CGBS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.44825
NANO-AntivirusTrojan.Win32.Zbot.dcchkf
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
AvastWin32:Kryptik-OTJ [Trj]
TencentMalware.Win32.Gencirc.10c7c0e1
Ad-AwareGen:Variant.Symmi.44825
ComodoTrojWare.Win32.Zbot.CGKA@5cxff4
DrWebTrojan.Siggen6.15132
ZillyaTrojan.Zbot.Win32.159993
TrendMicroTSPY_ZBOT.SMZH
McAfee-GW-EditionPWSZbot-FBTA!0FDDB24D4666
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-IPP
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.44825
JiangminTrojanSpy.Zbot.efly
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Symmi.DAF19
MicrosoftPWS:Win32/Zbot
GoogleDetected
AhnLab-V3Trojan/Win32.Necurs.R109444
BitDefenderThetaGen:NN.ZexaF.34606.wy1@aeThnblG
ALYacGen:Variant.Symmi.44825
MAXmalware (ai score=88)
VBA32TrojanSpy.Zbot
TrendMicro-HouseCallTSPY_ZBOT.SMZH
RisingTrojan.Kryptik!8.8 (TFE:2:OCSgoM3IDCK)
YandexTrojanSpy.Zbot!2atZfMDfB1E
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.CGEJ!tr
AVGWin32:Kryptik-OTJ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Symmi.44825?

Symmi.44825 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment