Malware

Symmi.74605 (file analysis)

Malware Removal

The Symmi.74605 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.74605 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Uzbek (Latin)
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself

Related domains:

msnsolution.nicaze.net

How to determine Symmi.74605?


File Info:

crc32: 4DB149AC
md5: 60582b561d55349f4611a2435f3d5516
name: 60582B561D55349F4611A2435F3D5516.mlw
sha1: 831f5f13d496db80b4bc315885980aab4504863b
sha256: 2159c4921bf2e57e5ec119f13f11bff7794cc45f18f38213f1bc9ede80457305
sha512: 6e38f166e52a84f1bb5243d692ff2a90862dca330724f7567fce50e80b3e1bcbe57b8e5f24fe066427663fdef3c8272b5b5f86eb35d561342e7b09958c02b129
ssdeep: 6144:chvm91XuL3W57OgFDVjQLTRh9F+e7flPwavYtsU82zwNZst9HiTh+2wZjUu04uY:ZZw69veahd2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Rog
FileVersion: 9.682.0514
CompanyName: LqofR3aP
ProductName: XxhMEg
ProductVersion: 9.682.0514
OriginalFilename: Rog.exe

Symmi.74605 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.IMspam.12
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.74605
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.1226
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Bulta.32a25eac
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.61d553
SymantecW32.Yimfoca.B
ESET-NOD32a variant of Win32/Injector.CYV
APEXMalicious
AvastWin32:AutoRun-BPN [Wrm]
KasperskyBackdoor.Win32.Androm.jpeh
BitDefenderGen:Variant.Symmi.74605
NANO-AntivirusTrojan.Win32.IMspam.ecacwd
MicroWorld-eScanGen:Variant.Symmi.74605
TencentMalware.Win32.Gencirc.114bf373
Ad-AwareGen:Variant.Symmi.74605
SophosML/PE-A + Mal/Generic-G
ComodoTrojWare.Win32.Jorik.~dy07@2nx31l
BitDefenderThetaAI:Packer.4F80F4681F
VIPRELooksLike.Win32.Malware!vb (v)
TrendMicroTROJ_JORIK.BN
McAfee-GW-EditionBehavesLike.Win32.Fareit.fm
FireEyeGeneric.mg.60582b561d55349f
EmsisoftGen:Variant.Symmi.74605 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.hhtq
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.72242B
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Symmi.D1236D
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
GDataGen:Variant.Symmi.74605
AhnLab-V3Trojan/Win32.Jorik.R12401
McAfeeGenericR-HHU!60582B561D55
MAXmalware (ai score=100)
VBA32BScope.Trojan.VBKrypt
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_JORIK.BN
YandexTrojan.Lolbot!KnTHCoO+Oqk
IkarusTrojan.Win32.VB
FortinetW32/VBInjector.W!tr
AVGWin32:AutoRun-BPN [Wrm]
Paloaltogeneric.ml

How to remove Symmi.74605?

Symmi.74605 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment