Norman Scanner Engine 5.90. 7
Sandbox 05.90, dated 21/01-2006
Your message ID (for later reference): 20060303-1241
nepenthes-dd5a39c1281a7a7cb0a1978aa5412fd8-za36WQ== : [SANDBOX] infected with unknown worm - W32/Poebot.J.dropper (Signature: W32/Poebot.J)
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Creating several executable files on hard-drive.
* File length: 90624 bytes.
* MD5 hash: dd5a39c1281a7a7cb0a1978aa5412fd8.
[ Changes to filesystem ]
* Deletes file C:\WINDOWS\SYSTEM32\firewall.exe.
* Creates file C:\WINDOWS\SYSTEM32\firewall.exe.
* Deletes file bkpxtcf.bat.
* Creates file bkpxtcf.bat.
* Deletes file C:\WINDOWS\SYSTEM32\algs.exe.
* Creates file C:\WINDOWS\SYSTEM32\algs.exe.
* Deletes file npcwxtow.bat.
* Creates file npcwxtow.bat.
[ Process/window information ]
* Creates a mutex link0907.
* Attemps to open bkpxtcf.bat NULL.
* Attemps to open npcwxtow.bat NULL.
[ Signature Scanning ]
* C:\WINDOWS\SYSTEM32\firewall.exe (90624 bytes) : W32/Poebot.J.
* bkpxtcf.bat (123 bytes) : no signature detection.
* C:\WINDOWS\SYSTEM32\algs.exe (90624 bytes) : W32/Poebot.J.
(C) 2004-2006 Norman ASA. All Rights Reserved.
The material presented is distributed by Norman ASA as an information source only.
Sent by removed@email.com to sandbox.
Received 3.Mar 2006 at 17.42 - processed 3.Mar 2006 at 20.38.