Malware

Symmi.56393 removal tips

Malware Removal

The Symmi.56393 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.56393 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Symmi.56393?


File Info:

name: 79D865F1BA7E0B196B68.mlw
path: /opt/CAPEv2/storage/binaries/be912d0de35241a0e1d75ab2906d09a6cbe67771ee43d10923fb46a976620daf
crc32: 1505FE5A
md5: 79d865f1ba7e0b196b685e95370be5e1
sha1: 0b6a87c4062622fee52cb5146e46f1e193ee38dc
sha256: be912d0de35241a0e1d75ab2906d09a6cbe67771ee43d10923fb46a976620daf
sha512: a2747ed33ea6ed5b7fd8ccf30100a400cfb2ff98867a315550f37bec3332504996b1a370a91339f1dc060617d0aa21b07bd259c65cfe1adb7e407b84da42f806
ssdeep: 6144:cPUDpE/Q7YOh6reRNVs6rUc5fPsrrqds9dqKhEF3:GUlQQ77Qms6z8rrqu81
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12294F12AF7D57831EBEED3B347D3D8BD451B9001126338AF298A07C888497A47F3655A
sha3_384: 09be0aa158b6a67c3866a747b67c94a04c6e17371a3b43a4002af75a288324334bcde6925f795d7016651b1ed621d34d
ep_bytes: 558bec81ec94010000bac40000008995
timestamp: 2012-04-03 01:25:14

Version Info:

CompanyName: Maskasaft Corporation
FileDescription: Maskasaft Visual Studie 2010
FileVersion: 1.9.43074.5121 built by: SP1Rel
InternalName: devenv.exe
LegalCopyright: © Maskasaft Corporation. All rights reserved.
OriginalFilename: devenv.exe
ProductName: Maskasaft® Visual Studio® 2010
ProductVersion: 1.9.43074.5121
Translation: 0x0409 0x04b0

Symmi.56393 also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGen:Variant.Symmi.56393
ClamAVWin.Trojan.Agent-1142043
FireEyeGeneric.mg.79d865f1ba7e0b19
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FBTA!79D865F1BA7E
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.39158
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1ba7e0
BaiduWin32.Trojan.Kryptik.je
VirITTrojan.Win32.Zbot.LWT
CyrenW32/A-b528930d!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CHLN
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Katusha.o
BitDefenderGen:Variant.Symmi.56393
NANO-AntivirusTrojan.Win32.Katusha.dcuezx
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
AvastWin32:MalOb-HX [Cryp]
RisingStealer.Zbot!8.109D7 (TFE:2:KQFyJ8IObjU)
Ad-AwareGen:Variant.Symmi.56393
TACHYONTrojan/W32.Katusha.431813
EmsisoftGen:Variant.Symmi.56393 (B)
ComodoTrojWare.Win32.PWS.Zbot.HC@5rvxmh
DrWebTrojan.Siggen6.15132
VIPREGen:Variant.Symmi.56393
TrendMicroTSPY_ZBOT.SMZH
McAfee-GW-EditionPWSZbot-FBTA!79D865F1BA7E
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-AIDA
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.56393
JiangminPacked.Win32.Katusha.f
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.57
ArcabitTrojan.Symmi.DDC49
MicrosoftPWS:Win32/Zbot
GoogleDetected
AhnLab-V3Trojan/Win32.ZBot.R114000
VBA32BScope.TrojanPSW.Zbot
ALYacGen:Variant.Symmi.56393
MAXmalware (ai score=86)
MalwarebytesTrojan.Zbot.Gen
TrendMicro-HouseCallTSPY_ZBOT.SMZH
TencentTrojan.Win32.Zbot.d
YandexTrojan.Kryptik!snlyUOw+G9w
IkarusTrojan.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CGEJ!tr
BitDefenderThetaGen:NN.ZexaF.34646.Au1@auF16ahG
AVGWin32:MalOb-HX [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.56393?

Symmi.56393 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment