Malware

What is “SwBndlr.Prepscram.S688820”?

Malware Removal

The SwBndlr.Prepscram.S688820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SwBndlr.Prepscram.S688820 virus can do?

  • Authenticode signature is invalid

How to determine SwBndlr.Prepscram.S688820?


File Info:

name: 291C2A2F6350DA17DBC2.mlw
path: /opt/CAPEv2/storage/binaries/22fc38a5282c4419474e93155ea5f1d90aed0dcbb52264e03e1c6b38a839a3a9
crc32: 8D7444D9
md5: 291c2a2f6350da17dbc2c3a21cc7bf70
sha1: e502fd08c75a08ebb304ec22cb6ba0624b807ec1
sha256: 22fc38a5282c4419474e93155ea5f1d90aed0dcbb52264e03e1c6b38a839a3a9
sha512: cdf376961527d75283f36c7cca0be1ca32621dc5d86f3f735634cd1a0dfd6c43b2e3a7065dc739011eb1a72eea5398df5e87fe695633e8be47be0297c249aee8
ssdeep: 6144:rR4tjhRNyLLSKVGWB2Vmgi7BGFvFQPW5vkcr:rRI7kLH89RFQPK84
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B848C12BA81D075D6B30234492AB75C82FEBD328DB6564777DC1F0E1FB02D1BA29672
sha3_384: ec63d248229b193e75f08e48e3481b5e72fcd6a0b312f7be32de86c5687ca6222ff9ce11306ed63264a68a5753f32176
ep_bytes: e8c8a90000e9000000006a146848061a
timestamp: 2017-02-22 13:08:05

Version Info:

0: [No Data]

SwBndlr.Prepscram.S688820 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.291c2a2f6350da17
CAT-QuickHealSwBndlr.Prepscram.S688820
McAfeeGenericRXAA-AA!291C2A2F6350
SangforTrojan.Win32.Save.a
VirITTrojan.Win32.Vittalia.SYX
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/IStartSurf.BF potentially unwanted
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
NANO-AntivirusRiskware.Win32.StartSurf.emllkn
ComodoApplication.Win32.IStartSurf.AP@759swi
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.moderate.ml.score
SophosGeneric PUA OF (PUA)
IkarusTrojan-Ransom.Torrentlocker
AviraTR/Crypt.XPACK.Gen
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3PUP/Win32.BundleInstaller.R199077
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic@AI.84 (RDML:A5zaoWBh+FJL139WoE9GtA)
YandexTrojan.GenAsa!kwb4whETk8w
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.f6350d

How to remove SwBndlr.Prepscram.S688820?

SwBndlr.Prepscram.S688820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment