Trojan

Trojan.Win32.Backswap.c removal guide

Malware Removal

The Trojan.Win32.Backswap.c is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Backswap.c virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Backswap.c?


File Info:

crc32: 2268D54C
md5: b2a9a38242943eca8210a5ba66da0fed
name: B2A9A38242943ECA8210A5BA66DA0FED.mlw
sha1: 3a116da2e547f97c737c8a9d7849fcbcd4bdc77a
sha256: b4c0b7f9a85f8863664e10e9d735bdaf0f3cce33da747b24b9655399844bf485
sha512: 716177feb9e4c142e92f9a3c58e15b628cc061303b22087274fc9f51cac540bb006f6a15057d0bc47687b4adce83b8988d14cf7b0f50cdeaac3ded325c9a13de
ssdeep: 6144:BGkQnsYW02QnZlmR75Yi2X3IQCn3fjA9VZFzUxXOdy/KkicWM+5npwv:BGNg026ZlmR70Y/k9VS+LPMf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2016 Igor Pavlov
InternalName: 7zFM
FileVersion: 16.02
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 16.02
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Backswap.c also known as:

K7AntiVirusTrojan ( 00523e7e1 )
LionicTrojan.Win32.Generic.4!c
ALYacTrojan.BackSwap.A
CylanceUnsafe
ZillyaTrojan.BackSwap.Win32.36
SangforTrojan.Win32.Backswap.c
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Backswap.90377d98
K7GWTrojan ( 00523e7e1 )
Cybereasonmalicious.242943
SymantecTrojan.Backswap
ESET-NOD32Win32/BackSwap.A
APEXMalicious
AvastWin32:Banker-NBQ [Trj]
ClamAVWin.Trojan.Backswap-6564636-0
KasperskyTrojan.Win32.Backswap.c
BitDefenderTrojan.GenericKD.30814416
NANO-AntivirusTrojan.Win32.Swrort.fcrgjr
ViRobotTrojan.Win32.S.BackSwap.495616.A
MicroWorld-eScanTrojan.GenericKD.30814416
TencentWin32.Trojan.Backswap.Pezh
Ad-AwareTrojan.GenericKD.30814416
SophosMal/Generic-S
ComodoMalware@#24k3qgfdmjuz2
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
FireEyeTrojan.GenericKD.30814416
EmsisoftTrojan.GenericKD.30814416 (B)
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASSuf.25192
MicrosoftTrojan:Win32/Bulta!rfn
ArcabitTrojan.Generic.D1D630D0
GDataTrojan.GenericKD.30814416
AhnLab-V3Malware/Win32.Generic.C2482787
McAfeeArtemis!B2A9A3824294
MAXmalware (ai score=94)
VBA32Trojan.Tiggre
PandaTrj/CI.A
YandexTrojan.ClipBanker!E285Jo9gVGo
IkarusTrojan-Banker.Backswap
FortinetW32/ClipBanker.CE!tr
AVGWin32:Banker-NBQ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Bulta.HgIASQsA

How to remove Trojan.Win32.Backswap.c?

Trojan.Win32.Backswap.c removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment