Threat Database Adware Adware.LinkSwift

Adware.LinkSwift

By GoldSparrow in Adware

Threat Scorecard

Ranking: 8,342
Threat Level: 20 % (Normal)
Infected Computers: 14,831
First Seen: September 12, 2013
Last Seen: July 17, 2025
OS(es) Affected: Windows

Adware.LinkSwift is an adware application that is known for displaying several coupon and online shopping deals. The Adware.LinkSwift ads will display at random sometimes offering outrageous deals. When clicked on, many of the Adware.LinkSwift ads will redirect users to unwanted sites or ones attempting to make other offers on shopping sites. Some of the Adware.LinkSwift ad links are viewed as being sponsored by other well-known sites like Google, Facebook and amazon. Removal of Adware.LinkSwift is an essential step to putting a stop to annoying ads and popups that may be displayed on a system infected with adware.

SpyHunter Detects & Remove Adware.LinkSwift

File System Details

Adware.LinkSwift may create the following file(s):
# File Name MD5 Detections
1. updateLinkSwift.exe dc4d31a8bab280a535376b7c44c81cd0 2,405
2. updater.exe 0b9c8589c0bcdd8ac33e177ef4f44a96 122
3. {25d71abf-7776-46f5-a269-9951331f9030}t.sys a8e2fe9a28a55db99f21a7fbe6a072a0 65
4. {25d71abf-7776-46f5-a269-9951331f9030}Gw.sys 96100423c810c537ff3658ec42420999 32
5. LinkSwiftBHO.dll 76f15760742c5f266c591c76897e7804 18
6. LinkSwift.Common.dll 2fe4fff249d0bb8b53c93c5025fdbe86 10
7. {25d71abf-7776-46f5-a269-9951331f9030}w64.sys daa52b7a4b7420baa97d6c8845eea1fc 8
8. {25d71abf-7776-46f5-a269-9951331f9030}Gw64.sys aea0d1ab9b4f603c803f046ed558c752 2
More files

Registry Details

Adware.LinkSwift may create the following registry entry or registry entries:
CLSID
{323420b6-65e5-4657-8106-a27392d4d4aa}
{339CA35C-F74A-44C3-BD78-9CE3E8C9C560}
{49FB101A-0A00-4E85-A807-8785C2D32604}
{62E29692-5062-40FE-9989-1A9E9B8F76A5}
File name without path
http_static.linkswift.co_0.localstorage
http_static.linkswift.co_0.localstorage-journal
Software\LinkSwift
Software\Microsoft\Internet Explorer\Approved Extensions\{323420B6-65E5-4657-8106-A27392D4D4AA}
Software\Microsoft\Internet Explorer\DOMStorage\linkswift.co
SOFTWARE\Microsoft\Tracing\updateLinkSwift_RASAPI32
SOFTWARE\Microsoft\Tracing\updateLinkSwift_RASMANCS
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{323420b6-65e5-4657-8106-a27392d4d4aa}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{323420B6-65E5-4657-8106-A27392D4D4AA}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{323420B6-65E5-4657-8106-A27392D4D4AA}
SOFTWARE\Wow6432Node\LinkSwift
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkSwift_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkSwift_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{323420b6-65e5-4657-8106-a27392d4d4aa}
SYSTEM\ControlSet001\services\eventlog\Application\Update LinkSwift
SYSTEM\ControlSet001\services\eventlog\Application\Util LinkSwift
SYSTEM\ControlSet001\services\Update LinkSwift
SYSTEM\ControlSet001\services\Util LinkSwift
SYSTEM\ControlSet002\services\eventlog\Application\Util LinkSwift
SYSTEM\ControlSet002\services\Util LinkSwift
SYSTEM\CurrentControlSet\services\eventlog\Application\Update LinkSwift
SYSTEM\CurrentControlSet\services\eventlog\Application\Util LinkSwift
SYSTEM\CurrentControlSet\services\Update LinkSwift
SYSTEM\CurrentControlSet\services\Util LinkSwift

Directories

Adware.LinkSwift may create the following directory or directories:

%PROGRAMFILES%\LinkSwift
%PROGRAMFILES(x86)%\LinkSwift
%TEMP%\LinkSwift

URLs

Adware.LinkSwift may call the following URLs:

LinkSwift

Trending

Most Viewed

Loading...