Malware

Swbndlr.Dlhelper.V4 information

Malware Removal

The Swbndlr.Dlhelper.V4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Swbndlr.Dlhelper.V4 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

alt.tubgiants.host
com.bushesstocking.icu

How to determine Swbndlr.Dlhelper.V4?


File Info:

name: 78631C8366747CA00148.mlw
path: /opt/CAPEv2/storage/binaries/036b5d74d94d8a93e9c06872f3dbacf7cd0452e4b0ecf17e0e4e893ca21d5aca
crc32: 7C57FCCC
md5: 78631c8366747ca0014807415ddc3740
sha1: fd767fb2d6e3fd2c4fd85bbceddef0879e486cdb
sha256: 036b5d74d94d8a93e9c06872f3dbacf7cd0452e4b0ecf17e0e4e893ca21d5aca
sha512: 3c6cab89336ff076dd9618469e69372b2cb504dfa40a6dcc72f2b625cbf15b8f39841d6d3eaca90578048fb81c340c82f785eb2d31d6bad481c54a0ad573659b
ssdeep: 24576:3H2WYm1jFuEwm3rPK+Y87sRPFxUiG1cqyZM+p2mJinNDVhfOhxEjiZSIzyr2q20n:Z1jkIcY6F817sj/S4fj4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174463322B56284BAE27743334894D66421BDFF306671596337E9970DEE309E1B2323B7
sha3_384: d9a8a36810faf4a36344be11f66ed6dfcf23d9c059a6a7febe3be5b18a26b3e07b8a5dc195cff37b9912918f95d32b48
ep_bytes: e815730000e97ffeffffff359cf0ad00
timestamp: 2016-01-19 23:47:04

Version Info:

ProductVersion: 4.8.9.7
FileVersion: 4.8.9.7
OriginalFilename: alreeteretrie.exe
LegalCopyright: ©Vnidio lyohenneraape ihtyotanohileb
InternalName: ALREETERETRIE.EXE
CompanyName: ©Vnidio lyohenneraape ihtyotanohileb
ProductName: ALREETERETRIE
Translation: 0x0409 0x04e4

Swbndlr.Dlhelper.V4 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.60753
CAT-QuickHealSwbndlr.Dlhelper.V4
ALYacGen:Variant.Barys.60753
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.90040
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/StartSurf.0f7eb9b6
K7GWTrojan ( 005464371 )
K7AntiVirusTrojan ( 005464371 )
CyrenW32/S-ce82fb66!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNDZ
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderGen:Variant.Barys.60753
NANO-AntivirusRiskware.Win32.StartSurf.flirgu
AvastWin32:StartSurf-I [Adw]
TencentMalware.Win32.Gencirc.10cc7f34
Ad-AwareGen:Variant.Barys.60753
SophosIStartSurfInstaller (PUA)
ComodoApplication.Win32.AdLoad.BF@808b6c
DrWebTrojan.Vittalia.17937
TrendMicroTrojanSpy.Win32.URSNIF.SMY.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
FireEyeGeneric.mg.78631c8366747ca0
EmsisoftGen:Variant.Barys.60753 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.60753
JiangminAdWare.StartSurf.twr
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.29F23D8
ArcabitTrojan.Barys.DED51
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.StartSurf.R249416
Acronissuspicious
McAfeePacked-FOY!78631C836674
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMY.hp
RisingTrojan.Kryptik!1.B51F (CLASSIC)
IkarusPUA.Downloader
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.GNDZ!tr
BitDefenderThetaGen:NN.ZexaF.34294.@x0@a0tRu1jG
AVGWin32:StartSurf-I [Adw]
Cybereasonmalicious.366747
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Swbndlr.Dlhelper.V4?

Swbndlr.Dlhelper.V4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment