Malware

How to remove “Symmi.91550”?

Malware Removal

The Symmi.91550 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.91550 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Symmi.91550?


File Info:

name: A874658F487A924F5D7B.mlw
path: /opt/CAPEv2/storage/binaries/f38ed8eb62ade3079f663594d44abcee01d85f59233b50f487995febd3b3d16a
crc32: FD19F721
md5: a874658f487a924f5d7befe7ad611d56
sha1: 2757d8fb30000e9c1aceae0ecfed38b1af1b8efe
sha256: f38ed8eb62ade3079f663594d44abcee01d85f59233b50f487995febd3b3d16a
sha512: f411633a8284c071492b3d1020a7d32b5437570f3c4deb04313b1979b3b81893aef6093c0560d82fc4c9fa78601eb9aa5a2745e53d12ae3402bfe08c2e2755fb
ssdeep: 98304:QGa0c7nRux1qPuuETFqGEEXQBG1ePmp6M/gQ6oiEcUVKGv:Q57c4uuETFElGymp6Md4EcUVKG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1153623375164108DE0E8CC3ED427BDE172FA166B8A91ECBC65BBF9C126228E5D613743
sha3_384: a92c5a9b762feb6d0c5d06f9a5badcb6b72578df649d3c9cd68b3e54f8e94aa57b23c9056ad6882e98721f775732b820
ep_bytes: 681362dc5be8ea7eecfff7d8e96b3d2e
timestamp: 2022-03-26 01:26:24

Version Info:

Translation: 0x0804 0x04b0
Comments: By Lele Chen. Mail:chlele66@qq.com
CompanyName: By Lele Chen
FileDescription: VBA封装exe示例
LegalCopyright: Copyright Reserved by Lele Chen.
ProductName: VBA示例
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 财务ERP-生产订单领料对比表+库存查询
OriginalFilename: 财务ERP-生产订单领料对比表+库存查询.exe

Symmi.91550 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Symmi.91550
FireEyeGeneric.mg.a874658f487a924f
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderGen:Variant.Symmi.91550
K7GWTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZevbaF.34638.@x0@aicneQkb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.CZ
APEXMalicious
RisingTrojan.Generic@AI.100 (RDMK:cmRtazr5V1y2vGPIZC0dvOykCL2+)
Ad-AwareGen:Variant.Symmi.91550
EmsisoftGen:Variant.Symmi.91550 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/VMProtBad-A
IkarusBackdoor.Hupigon
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Symmi.D1659E
GDataGen:Variant.Symmi.91550
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.C4081766
Acronissuspicious
ALYacGen:Variant.Symmi.91550
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!2bflRNRzLIc
SentinelOneStatic AI – Malicious PE
Cybereasonmalicious.f487a9

How to remove Symmi.91550?

Symmi.91550 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment