Malware

Should I remove “Symmi.95956”?

Malware Removal

The Symmi.95956 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.95956 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Symmi.95956?


File Info:

name: 1097C999C019E23512E0.mlw
path: /opt/CAPEv2/storage/binaries/c47d7161145c1d161941fe7f1c0b3fe580107457fc100c23a3e12ee963de4556
crc32: E32DEC54
md5: 1097c999c019e23512e0326171b15def
sha1: 112e915e00246e7c8d440e789b154e1613eef6f1
sha256: c47d7161145c1d161941fe7f1c0b3fe580107457fc100c23a3e12ee963de4556
sha512: 828f406fddcc6919bebfa1e7ac0101183c64cf59dc1344dd0b464da8b07ed33f45eb3362d94c6251c64bde5b853da2fd173b40e94b24126e97e34ce8942e796e
ssdeep: 6144:KVj+bLgZqL5I3VNXV0gIh8g2VbLIDG9r9l8jiAIEDpP5:KVjO+qL5oNulh2JLIqrry5IEDT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D14423085FAFAD72C407237AAE913919D34FE069C65285431950E73EDEF83406E6BD2B
sha3_384: aca7549452e3abbcfca9834747c8fec37490f9992f48c4758811c8575289eaf95e4e53c6ba323f534d7f202964affc16
ep_bytes: 60be00b046008dbe0060f9ffc7879ce0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Symmi.95956 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Bifrose.m!c
Elasticmalicious (moderate confidence)
DrWebBackDoor.Bifrost.19762
MicroWorld-eScanGen:Variant.Symmi.95956
FireEyeGeneric.mg.1097c999c019e235
CAT-QuickHealTrojan.Generic.20888
ALYacGen:Variant.Symmi.95956
VIPREGen:Variant.Symmi.95956
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/DelfInject.ali2000015
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.9c019e
BitDefenderThetaAI:Packer.026B795521
VirITTrojan.Win32.Generic.AVCB
CyrenW32/ABRisk.GCAN-5788
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ANDS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Bifrose-15815
KasperskyHEUR:Trojan.Win32.Refroso.gen
BitDefenderGen:Variant.Symmi.95956
NANO-AntivirusTrojan.Win32.Bifrose.bbmuho
AvastWin32:Epik-A [Drp]
TencentMalware.Win32.Gencirc.11511dc6
EmsisoftGen:Variant.Symmi.95956 (B)
F-SecureTrojan.TR/Graftor.59874
ZillyaBackdoor.Bifrose.Win32.76948
TrendMicroTROJ_GEN.R002C0DB123
McAfee-GW-EditionGenericRXCD-IK!23B391DECA12
Trapminemalicious.moderate.ml.score
SophosTroj/Zusy-Fam
GDataGen:Variant.Symmi.95956
JiangminTrojan/Generic.aiged
WebrootW32.Trojan.Gen
AviraTR/Graftor.59874
Antiy-AVLTrojan[Backdoor]/Win32.Bifrose
XcitiumTrojWare.Win32.Injector.TZM@4putks
ArcabitTrojan.Symmi.D176D4
ViRobotBackdoor.Win32.A.Bifrose.302847[UPX]
ZoneAlarmHEUR:Trojan.Win32.Refroso.gen
MicrosoftBackdoor:Win32/Bifrose.AE
CynetMalicious (score: 99)
McAfeeArtemis!1097C999C019
MAXmalware (ai score=88)
VBA32Trojan.Birfost
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DB123
RisingBackdoor.Bifrose!8.B24 (CLOUD)
YandexTrojan.GenAsa!f/xGqNITZRg
IkarusBackdoor.Win32.Bifrose
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.ZY!tr
AVGWin32:Epik-A [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.95956?

Symmi.95956 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment