Malware

What is “Symmi.45325”?

Malware Removal

The Symmi.45325 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.45325 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Symmi.45325?


File Info:

crc32: B2BD4A0C
md5: c28b21f577686f23c05e5f773c90c8d1
name: C28B21F577686F23C05E5F773C90C8D1.mlw
sha1: f7d4c3870803b041e4ffc996fda1b9c0c351e00c
sha256: be9bbbdc4529107bc5ba2416ceb70622f2197b87d65fbf21f963184882913743
sha512: 656b2881a3da16fd582f8f804958007e00ea0ceb776aab4da61c0aaa9e48787ec4821d78e22c90a942854db6fafc8c94ca703649dca7e42e6fb0d9b311e51e48
ssdeep: 6144:si3TujcJHWdOpXybDKCmwSQZZAkaoGqPpxsPMhbdlxKMo5f7e7JLEDVpjfSKSZK:EgJcAOKBvQZJJm/vMIhm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
InternalName: Glos
FileVersion: 7.02.0004
CompanyName: Please visit www.Appliance.org
ProductName: Elagatis
ProductVersion: 7.02.0004
FileDescription: Infangth disra
OriginalFilename: Glos.exe

Symmi.45325 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004ac1c01 )
Elasticmalicious (high confidence)
ClamAVWin.Malware.Nanobot-6918776-0
ALYacGen:Variant.Symmi.45325
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Symmi.45325
K7GWTrojan ( 004ac1c01 )
Cybereasonmalicious.577686
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.BLGS
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Napolar.auc
MicroWorld-eScanGen:Variant.Symmi.45325
Ad-AwareGen:Variant.Symmi.45325
SophosML/PE-A + Mal/VB-ANI
BitDefenderThetaAI:Packer.90A99A6621
VIPREVirTool.Win32.VBInject.acn (v)
McAfee-GW-EditionBehavesLike.Win32.Fareit.jh
FireEyeGeneric.mg.c28b21f577686f23
EmsisoftGen:Variant.Symmi.45325 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1130142
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Symmi.45325
AhnLab-V3Trojan/Win.MDA.R431263
McAfeeGeneric-FAUW!C28B21F57768
MAXmalware (ai score=83)
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BJGR!tr

How to remove Symmi.45325?

Symmi.45325 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment