Spy

About “Win32/Spy.Swisyn.GY” infection

Malware Removal

The Win32/Spy.Swisyn.GY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Swisyn.GY virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Spy.Swisyn.GY?


File Info:

crc32: 3C051F26
md5: 0de340ed01659ac9fca44d7726c8e7ec
name: 0DE340ED01659AC9FCA44D7726C8E7EC.mlw
sha1: 678b4e05af92257685f12461d1e75b61fd7d9e9e
sha256: 86df23978fe16a0d8c11737b9b902188f08ca94e9204dbd0283bf09f8a672de6
sha512: 40f246430d2a88b4f68ccbdd58c62d077203def9e25cb5a2bfbf7697772dc012316a5e00b02fe97c230cc515738f75cbd783b52fa0aefcc2c25a21fea3244dcd
ssdeep: 12288:UGZZDr2llFqZ63VH9NimwDTWRocFsr3ZeuSfm5v5nveEzk9/RQ5DqmXw/ZDb4/ee:xZv4B9NbMTWRoX3Uusm5RnveE0QG55iZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.Swisyn.GY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00276f081 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop1.64533
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.8KW@tz0C13ki
CylanceUnsafe
ZillyaTrojan.Buzus.Win32.69331
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Blocker.b0c8ed53
K7GWSpyware ( 00276f081 )
Cybereasonmalicious.d01659
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Swisyn.GY
APEXMalicious
AvastWin32:Delf-PYT [Trj]
ClamAVWin.Trojan.Agent-375905
KasperskyTrojan-Ransom.Win32.Blocker.alvi
BitDefenderGen:Trojan.Heur.8KW@tz0C13ki
NANO-AntivirusTrojan.Win32.Buzus.dqoiv
MicroWorld-eScanGen:Trojan.Heur.8KW@tz0C13ki
TencentMalware.Win32.Gencirc.10ba2f18
Ad-AwareGen:Trojan.Heur.8KW@tz0C13ki
SophosMal/Generic-S
ComodoBackdoor.Win32.Delf.~DP@1mio9l
BitDefenderThetaAI:Packer.2EE9C13D1C
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_Blocker.R002C0PE621
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FireEyeGeneric.mg.0de340ed01659ac9
EmsisoftGen:Trojan.Heur.8KW@tz0C13ki (B)
JiangminTrojan/Buzus.awwt
WebrootW32.Trojan.Gen
AviraDR/Delphi.Gen7
eGambitUnsafe.AI_Score_73%
KingsoftWin32.HeurC.KVM007.a.(kcloud)
MicrosoftVirTool:Win32/DelfInject
AegisLabTrojan.Win32.Buzus.lnay
GDataGen:Trojan.Heur.8KW@tz0C13ki
TACHYONTrojan/W32.DP-Buzus.991744
AhnLab-V3Trojan/Win32.Banload.R12397
McAfeeGenericRXHO-GL!0DE340ED0165
MAXmalware (ai score=100)
VBA32BScope.Trojan.Click
MalwarebytesPolyRansom.Virus.FileInfector.DDS
PandaGeneric Malware
TrendMicro-HouseCallRansom_Blocker.R002C0PE621
RisingRansom.Blocker!8.12A (TFE:5:Vdd2DcfShdH)
YandexTrojanSpy.Swisyn!tLovytKF/5c
IkarusVirus.Win32.DelfInject
FortinetW32/Injector.MOU!tr
AVGWin32:Delf-PYT [Trj]
Paloaltogeneric.ml

How to remove Win32/Spy.Swisyn.GY?

Win32/Spy.Swisyn.GY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment