Malware

How to remove “Mal/SwiftG-X”?

Malware Removal

The Mal/SwiftG-X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/SwiftG-X virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
www.dlptcn.cn
a.tomx.xyz

How to determine Mal/SwiftG-X?


File Info:

crc32: 33D7EC08
md5: 81a4a4e1fae43e561ecfe72267e196e3
name: _________.exe
sha1: 4b0365e7a4ea191018c214ea8ef751b7644e74ac
sha256: c2d521101efdb71bc1d5c16147f3e8d47ea97abee67ec5e7fdf5e0c682d77bf6
sha512: 6f35e7b06ece55989fded20349528de74617df43af318aeafead96d090adae925399ebbedf5aeaa4c64e56cbe513675aca7354ac0359603a2863cac48f420191
ssdeep: 98304:TF8aAe0yY2m0/7YAiE7LqA1WwV1VD66hlNWG:Tj7YAniA1v1D68Nz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: x5ba2x6237x7aef.exe
FileVersion: 17.2.6.0
OriginalFilename:
ProductVersion: 17.2.6.0
Translation: 0x0804 0x03a8

Mal/SwiftG-X also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Strictor.234435
McAfeePacked-GV!81A4A4E1FAE4
CylanceUnsafe
K7AntiVirusTrojan ( 00563cb01 )
BitDefenderGen:Variant.Strictor.234435
K7GWTrojan ( 00563cb01 )
CrowdStrikewin/malicious_confidence_80% (D)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Packed.Vmprotect-6762068-1
GDataGen:Variant.Strictor.234435
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Generic!8.C3 (TFE:dGZlOgWIW3UaD6QV7A)
Ad-AwareGen:Variant.Strictor.234435
SophosMal/SwiftG-X
F-SecureTrojan.TR/Black.Gen2
McAfee-GW-EditionBehavesLike.Win32.Backdoor.wc
FireEyeGeneric.mg.81a4a4e1fae43e56
EmsisoftGen:Variant.Strictor.234435 (B)
IkarusTrojan.Win32.VMProtect
AviraTR/Black.Gen2
Endgamemalicious (high confidence)
ArcabitTrojan.Strictor.D393C3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
ALYacGen:Variant.Strictor.234435
MAXmalware (ai score=84)
ESET-NOD32a variant of Win32/Packed.VMProtect.AB
BitDefenderThetaGen:NN.ZexaF.34122.QB0@auOaTYpj

How to remove Mal/SwiftG-X?

Mal/SwiftG-X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment