BitDefender Antivirus
Go

Trojan.Swizzor.DH

Spreading: medium
Damage: very low
Size: 10 KB
Discovered: 2005 Aug 27

SYMPTOMS:

Presence of registry key:
HKEY_CURRENT_USER\Software\warn surf bagsWay

HTTP download activity.

TECHNICAL DESCRIPTION:

The trojan usually comes from some web sites that contain adware content.

It downloads and installs adware applications from http://bins.lop.com/.

It may create registry key and subkeys in:
HKEY_CURRENT_USER\Software\warn surf bagsWay

Also it may launch Internet Explorer and go to certain websites for visiting purposes.

The downloader may be also detected as Memscan:Trojan.Swizzor.DH or Trojan.Downloader.Swizzor.DH.

Removal instructions:

Please let BitDefender delete files found infected.

ANALYZED BY:

Mihai Neagu, virus researcher