Trojan

Trojan.Win32.Swrort removal guide

Malware Removal

The Trojan.Win32.Swrort is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Swrort virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Trojan.Win32.Swrort?


File Info:

crc32: 5619DEFF
md5: 34355c5e6ce598dde445bc18ae23d6c6
name: 34355C5E6CE598DDE445BC18AE23D6C6.mlw
sha1: fc13974fc872097ad73856ebdea50d01a3dd0f7f
sha256: 3c4e584971278db079d45f837755c9a4abce12f61f738cdf15a7884a16009c0b
sha512: 03a26ab74036c8c6107c98b437b14baac4d7105ca8b78d9efb51e1db8d869d97ecd47017051def33712950e862f90a428f18b8c252c043898f62c4f878715a5f
ssdeep: 1536:A1ztk0Rd88i/UNy+4OXTnA5BXnAh5KCpl2dYvDM7g9z8mR2UmdCHsjjjjjjjj+q:AnFd0cI587pM0mmRGCMjjjjjjjj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: driseapoges.ots
FileVers: 25.26.361
Copyright: Copyrighz (C) 2020, pipkafug
TranslationUsa: 0x0471 0x011c

Trojan.Win32.Swrort also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35354164
FireEyeGeneric.mg.34355c5e6ce598dd
ALYacTrojan.GenericKD.35354164
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005738fd1 )
BitDefenderTrojan.GenericKD.35354164
K7GWTrojan ( 005738fd1 )
CyrenW32/Kryptik.CNB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan.Win32.Swrort.gen
AlibabaTrojan:Win32/Glupteba.9f78b8df
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.35354164
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.Agent.vxatu
DrWebTrojan.PWS.Stealer.26952
TrendMicroTrojan.Win32.WACATAC.USMANKN20
McAfee-GW-EditionBehavesLike.Win32.Injector.dz
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.vxatu
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.MK!MTB
ArcabitTrojan.Generic.D21B7634
ZoneAlarmHEUR:Trojan.Win32.Swrort.gen
GDataTrojan.GenericKD.35354164
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R356119
Acronissuspicious
McAfeeTrojan-FSWW!34355C5E6CE5
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHQR
TrendMicro-HouseCallTrojan.Win32.WACATAC.USMANKN20
RisingTrojan.Kryptik!1.CF5C (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_65%
FortinetW32/Glupteba.I!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.Dropper.028

How to remove Trojan.Win32.Swrort?

Trojan.Win32.Swrort removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment