Malware

Symmi.31944 removal

Malware Removal

The Symmi.31944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.31944 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Symmi.31944?


File Info:

name: A375383092C736E6F7EF.mlw
path: /opt/CAPEv2/storage/binaries/f99d2dcd467ffc6c26beffcb58310feb941b1e1b1fad827360803f981792892f
crc32: 58CED5BD
md5: a375383092c736e6f7efc0ac41cdf733
sha1: a393666fa80c940af662ef0a08bc889d6fd45a77
sha256: f99d2dcd467ffc6c26beffcb58310feb941b1e1b1fad827360803f981792892f
sha512: b7311d885cb38b1b3bde815dcf486bb6fcfe7604b1fcc14766018618124c2a15b85c45798290069292482cd17dd4546541f8eb68e16029e9b82a37222cdf9440
ssdeep: 6144:81+VmPaeGyhdtnspJhKmH80tSaqvKS0EmJDsxlimxE:84sSLEQpJhiCSASn+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16154D0E2A608C042D8356277CB11C85B832C1F369D9B3ABD516C3F58F3F42C25AD5EA9
sha3_384: 46783531582ede2ac1e7e26f55627c1de6b5430ec0a7bd12f1129cc5abd85f11e9d6bc78090cdee3fe5417ad4f183fb8
ep_bytes: 6856bb4000c347b9279523abec5dc955
timestamp: 2011-01-12 07:37:58

Version Info:

CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 5.7
InternalName: npp.exe
LegalCopyright: Copyleft 1998-2006 by Don HO
OriginalFilename: Notepad++.exe
ProductName: Notepad++
ProductVersion: 5.7
Translation: 0x0409 0x04b0

Symmi.31944 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.31944
FireEyeGeneric.mg.a375383092c736e6
McAfeePWS-Zbot.gen.qp
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.59594
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Kryptik.98eccab4
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Generic.BDVD
CyrenW32/S-aa63700b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ACZO
APEXMalicious
ClamAVWin.Trojan.Zbot-21567
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.31944
NANO-AntivirusTrojan.Win32.Zbot.rgeln
AvastWin32:Reveton-Y [Trj]
TencentMalware.Win32.Gencirc.10baddd4
SophosMal/Generic-R + Mal/EncPk-ABFO
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Siggen8.20373
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PAV22
McAfee-GW-EditionPWS-Zbot.gen.qp
EmsisoftGen:Variant.Symmi.31944 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.bnev
MaxSecureTrojan.Malware.3508004.susgen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.371DF8
MicrosoftPWS:Win32/Zbot!ml
ViRobotTrojan.Win32.A.Zbot.286720.K
GDataGen:Variant.Symmi.31944
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R20107
BitDefenderThetaGen:NN.ZexaF.34182.rm1@a84UlHbi
ALYacGen:Variant.Symmi.31944
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0PAV22
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.GenAsa!G/3YIhLJCCs
IkarusTrojan-Spy.Win32.Zbot
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.DGEQ!tr
WebrootW32.Malware.Gen
AVGWin32:Reveton-Y [Trj]
Cybereasonmalicious.092c73
PandaGeneric Malware

How to remove Symmi.31944?

Symmi.31944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment