Forum Discussion

jimmap's avatar
jimmap
Copper Contributor
Aug 01, 2026

Win32/Suweezy how is this still a thing with Win?

I am running win 11 on a surface pro 11.  Just discovered I got infected with 

Win32/Suweezy.  How is this possible?  This is a really old virus/Trojan horse.  Windows Defender should have caught this immediately.  Instead it got installed and it installed multiple bit miners.   I found it by running Quick Scan and it showed in the history it had already been quarentined twice recently.  I tried to run a full scan but it only ran for about 4 seconds.  Not a full scan.  I reset windows defender which did not help.  I then went into the excluded files and folders.  I tried to remove the exclude items the virus clearly installed with no luck.  Checking the registry, gminer and others are listed in the excluded but can't remove them.  I am now able to run what appears to be full scan and it has removed some of the miners.  Hopefully its all gone.  I keep running it after reboots to make sure its all gone.  I still can't clear the registry.  I guess I'll have to reinstall windows to clear it.  Just sucks that Defender failed so badly.  Let it install the virus and miner apps and exclude them from virus scan!  Seriously how is this possible?  FYI I think it got installed when I installed CrystalDiskMark app.  Just a guess as I don't download any files or go to bad websites.  yahoo, facebook, youtube is about it, oh and reddit.

2 Replies

  • Milanok's avatar
    Milanok
    Tin Contributor

    Win32/Suweezy is a Trojan downloader. Its primary job is to get onto your system and then download and install additional malicious software, like the cryptocurrency miners you found.

  • Defender’s quarantine entries do not mean it allowed the infection; they show detections, but persistent miners and exclusions you cannot remove mean the computer should still be treated as compromised. Disconnect it from networks and do not enter passwords. In Windows Security, review Protection history and remove any allowed threat, then inspect Virus & threat protection > Manage settings > Exclusions. Every exclusion weakens scanning; if they return or remain locked, stop troubleshooting inside the running system. Save work, run Microsoft Defender Offline from Scan options, then run a full scan after Windows restarts. From a clean device, change important passwords and revoke active sessions. Back up only documents, not executables or scripts. If miners, exclusions, or unusual services return, reinstall Windows from known-good media and restore clean data. Reinstall applications only from verified publisher sources. A four-second “full scan” is not reliable evidence that the device is clean.