Categories: Crack

Win32:SwPatch [Wrm] removal guide

The Win32:SwPatch [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:SwPatch [Wrm] virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32:SwPatch [Wrm]?


File Info:

crc32: 17A2E85Fmd5: 184713e3a7ce5fc7a0a15e2c561d8ee4name: update.exesha1: 898070e1c6b82d0d331a811312215db01cfc72bdsha256: bbce1b7406680c9e1c52ceb9eae0a01669e0f3c02792cefbc6875b538ce64962sha512: 7a2233e28a3559ce70e038561d9737b689079e518c6ba622f3103cedbc2729477b2d9f00736df3024c9a66c1cc7fa41a7f00049f0d1cd38367e6747fd9610ee2ssdeep: 1536:IORcYfDnmC1UB3wGf0mKBPsP1CbJ1lkMb+KR0Nc8QsJq39:lWYbnUD81BPq1CbJ1qe0Nc8QsC9type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009 The Apache Software Foundation.InternalName: ab.exeFileVersion: 2.2.14CompanyName: Apache Software FoundationComments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.ProductName: Apache HTTP ServerProductVersion: 2.2.14FileDescription: ApacheBench command line utilityOriginalFilename: ab.exeTranslation: 0x0409 0x04b0

Win32:SwPatch [Wrm] also known as:

Bkav W32.FamVT.RorenNHc.Trojan
MicroWorld-eScan Trojan.CryptZ.Gen
CAT-QuickHeal Trojan.Swrort.A
McAfee Swrort.i
Cylance Unsafe
VIPRE Trojan.Win32.Swrort.B (v)
SUPERAntiSpyware Trojan.Backdoor-PoisonIvy
Sangfor Malware
K7AntiVirus Trojan ( 0052a8581 )
K7GW Trojan ( 0052a8581 )
Cybereason malicious.3a7ce5
Invincea heuristic
F-Prot W32/Swrort.A.gen!Eldorado
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Swrort-5710536-0
GData Trojan.CryptZ.Gen
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:Win32/Rozena.e55462b1
NANO-Antivirus Virus.Win32.Gen-Crypt.ccnc
ViRobot Trojan.Win32.Elzob.Gen
Avast Win32:SwPatch [Wrm]
Tencent Win32.Trojan.Generic.Dxnb
Endgame malicious (high confidence)
Emsisoft Trojan.CryptZ.Gen (B)
Comodo TrojWare.Win32.Rozena.A@4jwdqr
F-Secure Trojan.TR/Crypt.EPACK.Gen2
DrWeb Trojan.Swrort.1
TrendMicro Backdoor.Win32.SWRORT.SMAL01
McAfee-GW-Edition BehavesLike.Win32.Swrort.lh
MaxSecure Trojan.Malware.121218.susgen
Trapmine malicious.high.ml.score
FireEye Generic.mg.184713e3a7ce5fc7
Sophos Mal/EncPk-TZ
SentinelOne DFI – Malicious PE
Cyren W32/Swrort.A.gen!Eldorado
Jiangmin Trojan.Generic.elimj
Webroot W32.Malware.Gen
Avira TR/Crypt.EPACK.Gen2
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.CryptZ.Gen
AegisLab Trojan.Win32.Generic.4!c
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Dynamer!rfn
AhnLab-V3 Trojan/Win32.Shell.R1283
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34090.eq1@au7XH2bi
ALYac Trojan.Agent.Rozena
MAX malware (ai score=100)
VBA32 Trojan.Swrort
Malwarebytes Trojan.Rozena
ESET-NOD32 a variant of Win32/Rozena.UL
TrendMicro-HouseCall Backdoor.Win32.SWRORT.SMAL01
Rising HackTool.Swrort!1.6477 (CLOUD)
Yandex Trojan.Rosena.Gen.1
Ikarus Trojan.Win32.Swrort
eGambit Unsafe.AI_Score_97%
Fortinet W32/Generic.AC.C0!tr
Ad-Aware Trojan.CryptZ.Gen
AVG Win32:SwPatch [Wrm]
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.08a

How to remove Win32:SwPatch [Wrm]?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Should I remove “Malware.AI.3914590665”?

The Malware.AI.3914590665 is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago

Trojan:Win32/Startpage.YT removal instruction

The Trojan:Win32/Startpage.YT is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

Win32/Injector.Autoit.FXP removal guide

The Win32/Injector.Autoit.FXP is considered dangerous by lots of security experts. When this infection is active,…

57 mins ago

Should I remove “Trojan.Agent.Delf.RVB”?

The Trojan.Agent.Delf.RVB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

IL:Trojan.MSILZilla.124965 malicious file

The IL:Trojan.MSILZilla.124965 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Generic.35601204 removal

The Trojan.Generic.35601204 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago