Norman Scanner Engine 5.90. 7
Sandbox 05.90, dated 21/01-2006
Your message ID (for later reference): 20060225-1523
nepenthes-69838e4bcf93b75c602852d25cf9d7da-eraseme_82717.exe : [SANDBOX] contains a security risk - W32/Downloader (Signature: NO_VIRUS)
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Anti debug/emulation code present.
* File length: 61952 bytes.
* MD5 hash: 69838e4bcf93b75c602852d25cf9d7da.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\win32ssr.exe.
* Creates file C:\U.exe.
[ Changes to registry ]
* Creates key "HKLM\Software\\Microsoft\\Windows".
* Sets value "MeltMe"="c:\sample.exe" in key "HKLM\Software\\Microsoft\\Windows".
* Creates key "HKLM\System\CurrentControlSet\Services\Win32Sr".
* Sets value "ImagePath"=""C:\WINDOWS\win32ssr.exe"" in key "HKLM\System\CurrentControlSet\Services\Win32Sr".
* Sets value "DisplayName"="Win32Sr" in key "HKLM\System\CurrentControlSet\Services\Win32Sr".
[ Network services ]
* Downloads file from http://http.down.love.witlog.com/tds.exe as C:\U.exe.
[ Security issues ]
* Starting downloaded file - potential security problem.
[ Process/window information ]
* Creates service "Win32Sr (Win32Sr)" as ""C:\WINDOWS\win32ssr.exe"".
[ Signature Scanning ]
* C:\WINDOWS\win32ssr.exe (61952 bytes) : no signature detection.
* C:\U.exe (4096 bytes) : no signature detection.
File downloaded from http://http.down.love.witlog.com/tds.exe - recognized as type PE_I386
nepenthes-69838e4bcf93b75c602852d25cf9d7da-eraseme_82717.exe_Download.tmp : W32/Rootkit.AI.dropper (Signature: W32/Agent.TRB)
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* File length: 26624 bytes.
* MD5 hash: 952e07ec0077f25ea55c844c38bb43ef.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\SYSTEM32\DRIVERS\netpt.sys.
[ Changes to registry ]
* Creates key "HKLM\System\CurrentControlSet\Services\NetPT".
* Sets value "ImagePath"="system32\DRIVERS\netpt.sys" in key "HKLM\System\CurrentControlSet\Services\NetPT".
* Sets value "DisplayName"="NetBIOS Protection" in key "HKLM\System\CurrentControlSet\Services\NetPT".
[ Process/window information ]
* Creates service "NetPT (NetBIOS Protection)" as "system32\DRIVERS\netpt.sys".
[ Signature Scanning ]
* C:\WINDOWS\SYSTEM32\DRIVERS\netpt.sys (3712 bytes) : W32/Rootkit.AI.
(C) 2004-2006 Norman ASA. All Rights Reserved.
The material presented is distributed by Norman ASA as an information source only.
Sent by removed@email.com to sandbox.
Received 25.Feb 2006 at 19.23 - processed 25.Feb 2006 at 19.39.