Norman Scanner Engine 5.83. 7
Sandbox 05.83, dated 27/08-2005
Your message ID (for later reference): 20050930-628
nepenthes-db98f3f4532a9e3a4e163ed474984e42-bar : [SANDBOX] infected with unknown worm - W32/P2PWorm (Signature: W32/Deadhat.A)
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Creating several executable files on hard-drive.
* File length: 55808 bytes.
[ Changes to filesystem ]
* Creates file C:\WINDOWS\SYSTEM\sms.exe.
* Creates file C:\progra~1\soulseek\myshar~1\test.exe
* \WinRar.exe.
[ Changes to registry ]
* Creates value "KernelFaultChk"="c:\sample.exe" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
[ Spreading through P2P networks ]
* P2P worm; drops files in P2P upload/download directory.
[ Process/window information ]
* Creates a mutex uu33WEEu.
* Creates a mutex Y&T.
* Will automatically restart after boot (I'll be back...).
* Attemps to open C:\WINDOWS\SYSTEM\sms.exe NULL.
(C) 2004 Norman ASA. All Rights Reserved.
The material presented is distributed by Norman ASA as an information source only.
Sent by removed@email.com to sandbox.
Received 30.Sep 2005 at 15.36 - processed 30.Sep 2005 at 15.36.