Trojan

How to remove “Trojan.Win32.Swisyn.cecm”?

Malware Removal

The Trojan.Win32.Swisyn.cecm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Swisyn.cecm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

How to determine Trojan.Win32.Swisyn.cecm?


File Info:

name: D2FDBAC2953D8EE38927.mlw
path: /opt/CAPEv2/storage/binaries/c66a201aa7175c91b0b86e03e5bcb728fb37fab3d15a801e6c26fbc06b85e594
crc32: 21ED686B
md5: d2fdbac2953d8ee389274a97fbe7bb9a
sha1: 5d31eac60882f38a708b0dcbc04cc484fdbc99c5
sha256: c66a201aa7175c91b0b86e03e5bcb728fb37fab3d15a801e6c26fbc06b85e594
sha512: d9c76e95cf119e6a4f9910f138ddcb91e31f8e64e3efa906bb520b81e9ce2d2e21c86bf276166f28da24453bab836e2d2971cf863ff1b912423dcf94cdfde9c5
ssdeep: 49152:yZk+P+WMD5vDKLUMDEEp9cD0QaSe+X7j474KHq3AB3BII7:yZbP+lD5bK4MgS90aSe+LcMuBRh7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116952217B2C1897AD3781BB4CC22AF5056767C311D44AE5EA399FA0C2D70393A8A774F
sha3_384: 68516379d45a16a4ec4f2d3b320163212726802fd4c96472b4d3c07a990ebe40785821fa823a68888e2d876b53756523
ep_bytes: 558bec83c4e833c08945e88945ecb820
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Swisyn.cecm also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Delf.l4mb
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d2fdbac2953d8ee3
ALYacGen:Trojan.Heur.RX.im0@XCJmUsoi
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Swisyn.Win32.29447
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Swisyn.4d66b346
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.2953d8
BitDefenderThetaAI:Packer.CF15A8D91F
VirITTrojan.Win32.Generic.AAJE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.FFEXTYN
Paloaltogeneric.ml
KasperskyTrojan.Win32.Swisyn.cecm
BitDefenderGen:Trojan.Heur.RX.im0@XCJmUsoi
NANO-AntivirusTrojan.Win32.Swisyn.oyfyz
APEXMalicious
RisingTrojan.Swisyn!8.630 (CLOUD)
Ad-AwareGen:Trojan.Heur.RX.im0@XCJmUsoi
EmsisoftGen:Trojan.Heur.RX.im0@XCJmUsoi (B)
ComodoMalware@#2x902zhualgfd
DrWebTrojan.Siggen3.41366
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosGeneric ML PUA (PUA)
JiangminTrojan/Genome.cdtd
WebrootW32.Malware.Gen
AviraTR/Crypt.FKM.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.E90737
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Trojan.Heur.RX.im0@XCJmUsoi
CynetMalicious (score: 100)
McAfeeArtemis!D2FDBAC2953D
TACHYONTrojan/W32.DP-Swisyn.2033664
VBA32Trojan.Swisyn
AvastWin32:Trojan-gen
TencentWin32.Trojan.Swisyn.Wstx
YandexTrojan.GenAsa!e6GYsZwLn1w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.235B24!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Swisyn.cecm?

Trojan.Win32.Swisyn.cecm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment