Malware

Symmi.7121 (file analysis)

Malware Removal

The Symmi.7121 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.7121 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Symmi.7121?


File Info:

crc32: A8EFEE98
md5: cfcb68cf4f318bd5d485686a82024464
name: CFCB68CF4F318BD5D485686A82024464.mlw
sha1: 69e9d31074e36dd7fd33cb5b134680687fc49917
sha256: 02e9bfcf4c7ed7adc71191c5d506532bd2b5615f372e76cb2228afae69178b47
sha512: 527d7b28d06ff9d4ef51b35b63a8b73890111f020f842e6fe3568f9aec8e1b416870a34892adf849cee493a7a3999cb45eb6a0f75ef600779de645341cdfb932
ssdeep: 49152:kiVDb51e5BZNitoL03o4VilM28TjFJspDLoVMgdk7Or:kOZ1erZbw0lFSFJspDLOMgdB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2007-2010 Google Inc.
InternalName: Google Update Setup
FileVersion: 1.3.33.7
CompanyName: Google Inc.
LanguageId: en
ProductName: Google Update
ProductVersion: 1.3.33.7
FileDescription: Google Update Setup
OriginalFilename: GoogleUpdateSetup.exe
Translation: 0x0409 0x04b0

Symmi.7121 also known as:

K7AntiVirusTrojan ( 003dc1641 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.58694
CynetMalicious (score: 100)
CAT-QuickHealTrojanToga.MUE.R9
ALYacGen:Variant.Symmi.7121
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 003dc1641 )
Cybereasonmalicious.f4f318
BaiduWin32.Trojan-Dropper.Injector.f
CyrenW32/S-24f4c04b!Eldorado
SymantecW32.Faedevour!inf
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
APEXMalicious
AvastWin32:Zbot-THZ [Trj]
ClamAVWin.Malware.Bzub-6727003-0
KasperskyBackdoor.Win32.Androm.qxe
BitDefenderGen:Variant.Symmi.7121
NANO-AntivirusTrojan.Win32.Androm.ctymsi
ViRobotWin32.Daws.B
MicroWorld-eScanGen:Variant.Symmi.7121
TencentBackdoor.Win32.Androm.qxe
Ad-AwareGen:Variant.Symmi.7121
ComodoTrojWare.Win32.Toga.PYF@7g9q1h
BitDefenderThetaGen:NN.ZexaF.34266.iw3@aG5JiKtP
McAfee-GW-EditionPWSZbot-FIB!CFCB68CF4F31
FireEyeGeneric.mg.cfcb68cf4f318bd5
EmsisoftGen:Variant.Symmi.7121 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Daws.byh
AviraTR/Dropper.Gen
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASBOL.CF5
MicrosoftTrojan:Win32/Occamy.C
GDataWin32.Trojan.PSE.12A3YX9
AhnLab-V3Backdoor/Win32.Androm.R226117
Acronissuspicious
McAfeePWSZbot-FIB!CFCB68CF4F31
MAXmalware (ai score=100)
VBA32BScope.Trojan.Autoit
MalwarebytesTrojan.Swisyn
PandaTrj/Genetic.gen
RisingDropper.Agent!1.AF79 (CLASSIC)
YandexTrojan.GenAsa!zFH4sqyAwHU
IkarusBackdoor.Win32.Androm
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.AQV!tr
AVGWin32:Zbot-THZ [Trj]
Paloaltogeneric.ml

How to remove Symmi.7121?

Symmi.7121 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment