Malware

Symmi.3798 information

Malware Removal

The Symmi.3798 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.3798 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:14962, :0, 127.0.0.1:19298
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Symmi.3798?


File Info:

name: 3F9AA109F67A09DD038F.mlw
path: /opt/CAPEv2/storage/binaries/ac01b9515e71dc18a0855fd496cc7e727d4f116fdd5bf8d64fe5f5f89a6820c8
crc32: 96FA1FC7
md5: 3f9aa109f67a09dd038fdb7e03f6c1e4
sha1: 28d850688c5bbaeaef935341b41a9de0bb8827ec
sha256: ac01b9515e71dc18a0855fd496cc7e727d4f116fdd5bf8d64fe5f5f89a6820c8
sha512: 3c5ebb8062ae25fc4174d41c396259bf9f7dd03422077a6ac4f5612e928922fd277666ea5241ddb822033f50b1b506af8e31a0c1f2a9a1eb2b2955f35199e757
ssdeep: 3072:acd5z4K1PoTsxBVVSHGJf682DCx90yKCY+o4Lej7iG/yh2iP27ssotg:9d5z4K9Msdn/uCH0yu+ej71iPY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A1402B6F861C536DE9F80F282820F45AE7D21B05A208543D7FDFEDDAC50AE1D52A217
sha3_384: 6159cf3c788fbbdb4d9e136e2028b5d8fc4ad314810b149576f865c7c182690a5ef65747ce9c887fcc45ac1d09798667
ep_bytes: 558bec6aff6830014300683492420064
timestamp: 2006-04-14 20:47:54

Version Info:

0: [No Data]

Symmi.3798 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
MicroWorld-eScanGen:Variant.Symmi.3798
FireEyeGeneric.mg.3f9aa109f67a09dd
ALYacGen:Variant.Symmi.3798
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Zbot.CI
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanPSW:Win32/TScope.772556e3
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.9f67a0
BitDefenderThetaGen:NN.ZexaF.34232.mmX@aqiGJxn
VirITTrojan.Win32.SHeur4.ARWD
CyrenW32/Trojan.BBDJ-0020
SymantecTrojan.Zbot!gen40
ESET-NOD32Win32/Spy.Zbot.AAO
TrendMicro-HouseCallTROJ_GEN.R002C0CB822
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-68057
KasperskyUDS:Trojan-Spy.Win32.Zbot.sb
BitDefenderGen:Variant.Symmi.3798
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Citadel-AG [Trj]
TencentWin32.Backdoor.Zbot.Auto
Ad-AwareGen:Variant.Symmi.3798
EmsisoftGen:Variant.Symmi.3798 (B)
ComodoMalware@#ehl7bwdh55eb
ZillyaTrojan.Zbot.Win32.82274
TrendMicroTROJ_GEN.R002C0CB822
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
SophosMal/Generic-R + Mal/Zbot-IW
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.3798
JiangminTrojanSpy.Zbot.chwt
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.13A43E
KingsoftWin32.Troj.Zbot.fz.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
ViRobotTrojan.Win32.A.Zbot.200704.BK
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 99)
Acronissuspicious
McAfeeGenericRXDS-WF!3F9AA109F67A
TACHYONTrojan-Spy/W32.ZBot.200704.BC
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!oDT3FNqLvzQ
IkarusTrojan-Spy.Win32.Zbot
eGambitGeneric.Malware
FortinetW32/Zbot.ASJ!tr
AVGWin32:Citadel-AG [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Symmi.3798?

Symmi.3798 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment