Malware

What is “Symmi.3781”?

Malware Removal

The Symmi.3781 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.3781 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Symmi.3781?


File Info:

name: 8ABF32E6EE85ABA1643E.mlw
path: /opt/CAPEv2/storage/binaries/a9b11fdccdc040db60f9f4d130bc722ec1f09d19dce2b698a5e1d0925d095fc0
crc32: 465E4993
md5: 8abf32e6ee85aba1643e622408e6caed
sha1: 06f658839d858dd9f65494d075b453ae312f53ec
sha256: a9b11fdccdc040db60f9f4d130bc722ec1f09d19dce2b698a5e1d0925d095fc0
sha512: 741db3dec6c6c65be0cf3690f110542d4955297fed26f40c12b62e944b342fcda0f57e90b1b7e7410af95dc979aa230a23daad984bc263a8d1c140e08e5d7f3d
ssdeep: 6144:0eF8uogxcSKHTXhx0MM20KW3dxJjXUtkn5Fb7c0/a1pC3RI0pK:kQBKHToMM2qtx5XUWn5Fb7c0i1Mb8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D648C3BFA81E8B9F04B1138CC27C6FD55667D91DE9422973AEA3F0FB136B524818185
sha3_384: 33abc1cf7997a04c3a0e2fdce9954a7bf583434fb314097403d99f4ddd56fb9de8183360bbd2b8af8ac0e2f3d87dce66
ep_bytes: 6a606810714300e8d8080000bf940000
timestamp: 2012-10-10 04:41:25

Version Info:

CompanyName: Until
FileDescription: Until sleep
FileVersion: 0.7.379.73
LegalCopyright: © 2002 Until, Inc. All Rights Reserved.
InternalName: sleep
OriginalFilename: children.exe
ProductName: Until sleep
ProductVersion: Follow
Translation: 0x0409 0x04b0

Symmi.3781 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.3781
FireEyeGeneric.mg.8abf32e6ee85aba1
McAfeePWS-Zbot.gen.aoi
CylanceUnsafe
SangforARMADILLO17
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.6ee85a
VirITTrojan.Win32.Generic.AFW
CyrenW32/S-bd019db3!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ANQA
APEXMalicious
ClamAVWin.Trojan.Menti-3706
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.3781
NANO-AntivirusTrojan.Win32.Panda.dpiqvs
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Symmi.3781
TACHYONTrojan/W32.Menti.311296.D
EmsisoftGen:Variant.Symmi.3781 (B)
ComodoMalware@#3raxpmrb8jtep
DrWebTrojan.PWS.Panda.2401
ZillyaTrojan.Menti.Win32.39729
McAfee-GW-EditionPWS-Zbot.gen.aoi
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-IU
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.3781
JiangminTrojan/Menti.aayf
AviraTR/Crypt.ZPACK.Gen8
ViRobotTrojan.Win32.A.Menti.311296.Y
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.tq0@aq5fDdai
ALYacGen:Variant.Symmi.3781
MAXmalware (ai score=86)
VBA32Trojan.Menti
RisingTrojan.Generic@AI.86 (RDML:5/KgXkBPLLX4c0G5Q2UVcg)
YandexTrojan.Kryptik!pPbCDtdMyBw
IkarusWorm.Win32.Gamarue
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AQJ!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Symmi.3781?

Symmi.3781 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment