Malware

Symmi.7206 removal

Malware Removal

The Symmi.7206 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.7206 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Installs OpenCL library, probably to mine Bitcoins
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Symmi.7206?


File Info:

name: 2A52392CD0968A8746CC.mlw
path: /opt/CAPEv2/storage/binaries/c2505567f9edfc66e79eca75201524bb6f019694eb8b21dddd7f4274be660d35
crc32: 7A94D8C1
md5: 2a52392cd0968a8746cc7ce8eb8a9142
sha1: 275f0a6a8918d7216a406f6be4c19e2a4c42e489
sha256: c2505567f9edfc66e79eca75201524bb6f019694eb8b21dddd7f4274be660d35
sha512: 241ca8e13328084959c7541bc8dd5f0744a0b10dc4455708926504b618a2f8bac52f3c0d1943f017f36d54acd92c703379d0c8aa8914e79e71ac043d388d3b13
ssdeep: 49152:7nDB1t1wEPRoav+/toN/p10vQYLF/UtsKHrepJ:7TPRonO/p6vhJ0TSpJ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10C753381B5641470E74310700DC399AFEAE51C5F4FB2AE56CB0649EB2A6DA36FB1834F
sha3_384: 0f76acf3bbba047c62fe4e830f86d95e534e71204fb662d182fd59db1e09aa41a254630e0f12b3d478a134d4b899f3af
ep_bytes: 558bec6aff68e0704000689065400064
timestamp: 2010-11-18 18:41:51

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX small
FileVersion: 9.20
InternalName: 7zS2.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS2.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Symmi.7206 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Swizzor.based
MicroWorld-eScanGen:Variant.Symmi.7206
FireEyeGeneric.mg.2a52392cd0968a87
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.34742.NrW@aCSThVdi
ESET-NOD32a variant of Win32/Nebuler.DU.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0GFG22
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Symmi.7206
NANO-AntivirusTrojan.Win32.Swizzor.cbwasg
AvastWin32:Malware-gen
TencentWin32.Trojan.Spnr.Hrpa
SophosML/PE-A
ComodoMalware@#6mjllqf6f5jb
TrendMicroTROJ_GEN.R03BC0GFG22
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious SFX
EmsisoftGen:Variant.Symmi.7206 (B)
IkarusWin32.Malware
JiangminTrojan/Agent.inhd
AviraHEUR/AGEN.1205550
KingsoftWin32.HeurC.KVM099.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Symmi.7206
McAfeeArtemis!2A52392CD096
VBA32Trojan.Swizzor
MalwarebytesTrojan.Agent.KG
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:A5Gfee1EOSNzWU4DYDpvEQ)
MAXmalware (ai score=82)
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Kryptik.BFOP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.cd0968
PandaTrj/Genetic.gen

How to remove Symmi.7206?

Symmi.7206 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment