Malware

Symmi.64255 removal instruction

Malware Removal

The Symmi.64255 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.64255 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Symmi.64255?


File Info:

name: 77BAC71DC3E583109274.mlw
path: /opt/CAPEv2/storage/binaries/02272b16170596a1b5a0c1e14d5f52fc134e8e4dbd37ba1abf8859fcb929d8ee
crc32: 7C6F4F7F
md5: 77bac71dc3e583109274bacd765ff0f8
sha1: 0630bdbe7a55fa73265280198683f9fcf6b19a0d
sha256: 02272b16170596a1b5a0c1e14d5f52fc134e8e4dbd37ba1abf8859fcb929d8ee
sha512: 6d481b1c4ebf77fbde7230d0487b8329c74f71a53f0ead44f62d83cfc21deabb199e5c4c2b88f18a14b1a5c439984125c54d64bb31f40495d72d5610b69d8d75
ssdeep: 12288:XS5WWLDG+5w9mle4825XV3IcE1kfgjdlA:CZLDHDH8CfgjU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CA48E77F6D18433D26329789D5B57A89C3ABE503D28784A6BE83C8C5F393813439297
sha3_384: a841f8d499c6f209e39bb70695b415e216e45fa19c8e3a4e4368bb10173539467521c94773cb0945509958e6fa702180
ep_bytes: 558bec83c4f0b8f4d04400e8b88dfbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Symmi.64255 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.64255
FireEyeGeneric.mg.77bac71dc3e58310
McAfeeGenericRXST-TX!77BAC71DC3E5
CylanceUnsafe
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.dc3e58
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.YTV
APEXMalicious
ClamAVWin.Downloader.Jaik-9947471-0
KasperskyHEUR:Trojan-Downloader.Win32.Convagent.gen
BitDefenderGen:Variant.Symmi.64255
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10d03e4a
Ad-AwareGen:Variant.Symmi.64255
EmsisoftGen:Variant.Symmi.64255 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
DrWebTrojan.Siggen17.44917
TrendMicroTROJ_GEN.R014C0WDQ22
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Banload
GDataWin32.Trojan.PSE.121UZQG
AviraTR/Dldr.Banload.jxcvi
MAXmalware (ai score=83)
ZoneAlarmHEUR:Trojan-Downloader.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Banload.R487425
BitDefenderThetaGen:NN.ZelphiF.34638.BGW@ae53AwbG
ALYacGen:Variant.Symmi.64255
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.2236139952
TrendMicro-HouseCallTROJ_GEN.R014C0WDQ22
RisingDownloader.Generic!8.141 (TFE:dGZlOgV3Tw92b3L74g)
YandexTrojan.GenAsa!1ucsWzAoHVM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Symmi.64255?

Symmi.64255 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment