Malware

What is “Symmi.5056”?

Malware Removal

The Symmi.5056 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.5056 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Symmi.5056?


File Info:

name: 41956E66703CD60A1120.mlw
path: /opt/CAPEv2/storage/binaries/a6ee4cd76e5d683c331f412fb1bb209e1383a380c22180d5de5ee015e0eb0eb2
crc32: 7353213E
md5: 41956e66703cd60a112043330d89bddd
sha1: f65f07214b827963e9652cd913aa67da5d2c25c4
sha256: a6ee4cd76e5d683c331f412fb1bb209e1383a380c22180d5de5ee015e0eb0eb2
sha512: a1f756250edf98642ab89964fb3f5f0cb5c4e0b18e375a868c7126c477123a0940168ded9731a0e1fe097c2fda30ba08b014d3b672f4efb308bbfe7d0b8b5e7a
ssdeep: 6144:JqIlbOt2tzzKmffx6Fa6Fir7+XviuoRNlmi:gIlPOsHWGVmi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B14011535B4A06FE5A062F9283CC2FA9079FECA265A3217D3705F5E681A1FCC20D977
sha3_384: 9b793eafa83594e55404458f6bb131e6cb450591e577c3e2be92c7ce5ea6ac560203caf652456b43a9104d12443ac224
ep_bytes: 833d6cc4420000753f8b155dc4420085
timestamp: 1992-06-19 04:10:01

Version Info:

0: [No Data]

Symmi.5056 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.2363
MicroWorld-eScanGen:Variant.Symmi.5056
FireEyeGeneric.mg.41956e66703cd60a
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Symmi.5056
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.83342
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f23c1 )
AlibabaTrojanPSW:Win32/Kryptik.2f8413de
K7GWTrojan ( 0040f23c1 )
Cybereasonmalicious.6703cd
BitDefenderThetaGen:NN.ZexaF.34212.mGX@aWlQ7zak
VirITTrojan.Win32.SMSSend.DMX
CyrenW32/DelfInject.AM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AMTR
TrendMicro-HouseCallTSPY_ZBOT.WYD
Paloaltogeneric.ml
ClamAVWin.Packed.Zbot-9890662-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.5056
NANO-AntivirusTrojan.Win32.Tishop.bbuqxt
SUPERAntiSpywareTrojan.Agent/Gen-Cryptic
AvastWin32:Spyware-gen [Spy]
TencentWin32.Trojan.Generic.Pbpd
Ad-AwareGen:Variant.Symmi.5056
EmsisoftGen:Variant.Symmi.5056 (B)
ComodoTrojWare.Win32.Kryptik.AOKV@4sn0fa
BaiduWin32.Adware.Kryptik.c
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.WYD
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SophosMal/Generic-R + Troj/Mdrop-ETG
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.5056
WebrootW32.Malware.Gen
AviraDR/Delphi.Gen8
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.28B94
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R37545
Acronissuspicious
McAfeePWS-Zbot.gen.aey
TACHYONTrojan-Spy/W32.ZBot.200193.F
VBA32Malware-Cryptor.Limpopo
MalwarebytesSpyware.ZeuS
APEXMalicious
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.GenAsa!KSVk2u3jK3U
IkarusTrojan-PWS.Win32.Zbot
eGambitUnsafe.AI_Score_97%
FortinetW32/Zbot.EQPB!tr
AVGWin32:Spyware-gen [Spy]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.4809554.susgen

How to remove Symmi.5056?

Symmi.5056 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment