Adware

Adware:Win32/Swiminen removal guide

Malware Removal

The Adware:Win32/Swiminen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Swiminen virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Adware:Win32/Swiminen?


File Info:

name: B2D326E8DA7908E0CA17.mlw
path: /opt/CAPEv2/storage/binaries/26f5df29472903ac5383f877b807bcae4c961cd1d6c3b7581d1bbea73d6de629
crc32: F0019DE4
md5: b2d326e8da7908e0ca179f858e797a8a
sha1: 36bc6111512f204cd59023396eeb4598db278f9a
sha256: 26f5df29472903ac5383f877b807bcae4c961cd1d6c3b7581d1bbea73d6de629
sha512: 93f96513ccbe282d915d06fba562352837616cd194d5d2d5b0e60818114c2f10da3a46f5d2312ed8e5a439477307055ca15d6bd5f290a9f7018100031a000a60
ssdeep: 12288:rBvbAqcK0+GE5heBG937oi3fxHR6QT4ePCiikwGpj/LoKG6/oFXUY43lcU0L2:rxUaLN0G93hfxp4eqiikxj/Lo5jEY43D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5E4230F6A166C14FBC0487390F51A5B5E2772E359D6A8D5C0CECCC32BB69E0179CAA9
sha3_384: 9c1cb17219fe54385eb736656ccaeb728b884fd6c8ff0e3479d74d163b3d29d0dfe9ead9154aa725def4c9229cef35b4
ep_bytes: 60be00c04f008dbe0050f0ffc787bc57
timestamp: 2020-02-03 10:55:04

Version Info:

CompanyName: 上海永楚网络科技有限公司
FileDescription: 拷贝兔核心服务
FileVersion: 1.0.0.1
InternalName: Services.exe
LegalCopyright: Copyright (C) 2019 上海永楚网络科技有限公司
OriginalFilename: Services.exe
ProductName: 拷贝兔
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Adware:Win32/Swiminen also known as:

FireEyeTrojan.GenericKD.44495882
McAfeeGenericRXAA-FA!B2D326E8DA79
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWAdware ( 005678571 )
K7AntiVirusAdware ( 005678571 )
ESET-NOD32a variant of Win32/Kaobeitu.D potentially unwanted
APEXMalicious
BitDefenderTrojan.GenericKD.44495882
NANO-AntivirusRiskware.Win32.WDJiange.hjcxme
MicroWorld-eScanTrojan.GenericKD.44495882
AvastWin32:AdwareX-gen [Adw]
RisingAdware.Agent!1.C1A5 (CLASSIC)
Ad-AwareTrojan.GenericKD.44495882
SophosGeneric PUA DG (PUA)
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.44495882 (B)
GDataTrojan.GenericKD.44495882
WebrootPua.Gen
AviraHEUR/AGEN.1137501
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.CoinMiner
ArcabitTrojan.Generic.D2A6F40A
MicrosoftAdware:Win32/Swiminen
AhnLab-V3PUP/Win32.RL_AdLoad.R356480
ALYacTrojan.GenericKD.44495882
MalwarebytesMalware.AI.2105243043
YandexRiskware.Agent!OuN0PKdbtgU
IkarusTrojan-Downloader.Win32.Adload
FortinetRiskware/Generic_PUA_DG
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.8da790
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.74818813.susgen

How to remove Adware:Win32/Swiminen?

Adware:Win32/Swiminen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment