Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 26 November 2009 12:35:24 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Swimnag-A is a worm for the Windows platform.
W32/Swimnag-A includes functionality to:
- run automatically
- create files in the <WINDOWS>\system32 folder
- access the internet and communicate with a remote server via HTTP
When W32/Swimnag-A is installed it creates the file <System>\cbdaabfbcebebcddbd.dll.
The following registry entries are created to run code exported by cbdaabfbcebebcddbd.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
DllName
<System>\cbdaabfbcebebcddbd.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
Impersonate
0x00000000
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbdaabfbcebebcddbd
Startup
lk
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Blud
jA+VGWaVky02mODUSiU4Gnr6VQ4Gn62atQ3IfWKDWsyk7zTELFtSGQ+CQ9tGLMdLzHlKn9Oi2b3LHl0aAbX5Um6AlKfqXaUyx8GANV5eUuniIAL6b0YbBC74Dy5gPX5gH3p6pMoJGg1T42tMcZaIhtP6Nuw9j/7czbmUbQ+b8WCwOOjhyE8kzDU+UvWmiYt+ZMjukXVrQ5/IrNJan1EhFmzKt

