Antivirus and Security Software from Sophos

Sophos blogs

W32/Swimnag-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 26 November 2009 12:35:24 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Swimnag-A is a worm for the Windows platform.

W32/Swimnag-A includes functionality to:

- run automatically
- create files in the <WINDOWS>\system32 folder
- access the internet and communicate with a remote server via HTTP

When W32/Swimnag-A is installed it creates the file <System>\cbdaabfbcebebcddbd.dll.

The following registry entries are created to run code exported by cbdaabfbcebebcddbd.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
DllName
<System>\cbdaabfbcebebcddbd.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
Impersonate
0x00000000

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
Startup
lk

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Blud
jA+VGWaVky02mODUSiU4Gnr6VQ4Gn62atQ3IfWKDWsyk7zTELFtSGQ+CQ9tGLMdLzHlKn9Oi2b3LHl0aAbX5Um6AlKfqXaUyx8GANV5eUuniIAL6b0YbBC74Dy5gPX5gH3p6pMoJGg1T42tMcZaIhtP6Nuw9j/7czbmUbQ+b8WCwOOjhyE8kzDU+UvWmiYt+ZMjukXVrQ5/IrNJan1EhFmzKt

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer