Analysis Report for stormcodec4117.exe

Summary:

File Name: stormcodec4117.exe
File size: 236649 bytes
MD5: ed29dc773f6e03958f9b85b160a8cfdf
SHA1: d6cbbc64623ced430c2945cda11b0ba1d71a6ef9
PEiD: -

VirusTotal Result: 10/32 (31.25%)
AntiVir 7.6.0.75 2008.03.26 HEUR/Malware
Avast 4.7.1098.0 2008.03.26 Win32:DNSChanger-SF
BitDefender 7.2 2008.03.26 Dropped:Trojan.Downloader.Zlob.ABOU
F-Prot 4.4.2.54 2008.03.26 W32/Trojan2.AIES
F-Secure 6.70.13260.0 2008.03.26 W32/Malware
Kaspersky 7.0.0.125 2008.03.26 Trojan.Win32.DNSChanger.arn
Norman 5.80.02 2008.03.26 W32/Malware
Prevx1 V2 2008.03.26 Generic.Dropper.xCodec
VBA32 3.12.6.3 2008.03.25 MalwareScope.Trojan.DnsChange.2
Webwasher-Gateway 6.6.2 2008.03.26 Heuristic.Malware

 

Autostart capabilities: This executable registers processes to be executed at system start. This could result in unwanted actions to be performed automatically.



Table of Contents

1. General Information

 

- Information about Anubis' invocation

 

Time needed:

240 s 

Report created:

03/26/08, 19:13:10 

Termination reason:

Timeout 

Program version:

1.5 

2. stormcodec4117.exe

 

- General information about this executable

 

Analysis Reason:

Primary Analysis Subject 

Filename:

stormcodec4117.exe 

MD5:

ed29dc773f6e03958f9b85b160a8cfdf 

SHA-1:

d6cbbc64623ced430c2945cda11b0ba1d71a6ef9 

File Size:

236649 Bytes

Command Line:

C:\stormcodec4117.exe  

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00B10000 

0x00009000 

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\dcryptdll.dll 

0x10000000 

0x00007000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\MSCTF.dll 

0x74720000 

0x0004B000 

C:\WINDOWS\system32\RichEd20.dll 

0x74E30000 

0x0006C000 

C:\WINDOWS\system32\msctfime.ime 

0x755C0000 

0x0002E000 

C:\WINDOWS\system32\SHFOLDER.dll 

0x76780000 

0x00009000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

C:\WINDOWS\system32\OLEAUT32.DLL 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\SETUPAPI.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 


 

- Popups

 

Window Name

Window Text

VideoKey Setup  

I &Agree Cancel Nullsoft Install System v2.35 Nullsoft Install System v2.35 License Agreement Please review the license terms before installing VideoKey. Press Page Down to see the rest of the agreement. LICENSE AGREEMENT ! YOU SHOULD CAREFULLY READ THE FOLLOWING TERMS AND CONDITIONS BEFORE USING THIS PRODUCT. IT CONTAINS SOFTWARE, THE USE OF WHICH IS LICENSED BY LICENSOR TO ITS CUSTOMERS FOR THEIR USE ONLY AS SET FORTH BELOW. IF YOU DO NOT AGREE TO THE TERMS AND CONDITIONS OF THIS AGREEMENT, DO NOT USE THE SOFTWARE. USING ANY PART OF THE SOFTWARE INDICATES THAT YOU ACCEPT THESE TERMS. THE PRODUCT IS PROVIDED "AS IS". THERE ARE NO WARRANTIES UNDER THIS AGREEMENT, AND LICENSOR DISCLAIMS ANY IMPLIED WARRANTY OF MERCHANTABILITY OR FITNESS FOR PARTICULAR PURPOSE. GRANT OF LICENSE: Licensor grants to you this personal, limited, non-exclusive, non-transferable, non-assignable license solely to use in a single copy of the Licensed Works on a single computer for use by a single concurrent user only, and solely provided that you adhere to all of the terms and conditions of this Agreement. "Licensed Works" means computer software together with any related documentation (including design, systems and user) and other materials for use in connection with such computer software in this package. The foregoing is an express limited use license and not an assignment, sale, or other transfer of the Licensed Works or any Intellectual Property Rights (as defined below) of Licensor. ASSENT: By opening the file package containing this software, you agree that this Agreement is a legally binding and valid contract, agree to abide by the intellectual property laws and all of the terms and conditions of this Agreement, and further agree to take all necessary steps to ensure that the terms and conditions of this Agreement are not violated by any person or entity under your control or in your service. OWNERSHIP OF SOFTWARE: The Licensor and/or its affiliates or subsidiaries own certain rights that may exist from time to time in this or any other jurisdiction, whether foreign or domestic, under patent law, copyright law, publicity rights law, moral rights law, trade secret law, trademark law, unfair competition law or other similar protections, regardless of whether or not such rights or protections are registered or perfected (the "Intellectual Property Rights"), in the Licensed Works. ALL INTELLECTUAL PROPERTY RIGHTS IN AND TO THE LICENSED WORKS ARE AND SHALL REMAIN IN LICENSOR. NO COMMERCIAL USE: This License Agreement grants you the right to use the software for personal use only. Commercial use of the software or of the work products resulting from its use is not permitted under this License Agreement. RESTRICTIONS: (a) You are expressly prohibited from copying, modifying, merging, selling, leasing, redistributing, assigning, or transferring in any matter, Licensed Works or any portion thereof. (b) You may take a single copy of materials within the package or otherwise related to Licensed Works only as required for backup purposes. (c) You are also expressly prohibited from reverse engineering, decompiling, translating, disassembling, deciphering, decrypting, or otherwise attempting to discover the source code of the Licensed Works as the Licensed Works contain proprietary material of Licensor. You may not otherwise modify, alter, adapt, port, or merge the Licensed Works. (d) You may not remove, alter, deface, overprint or otherwise obscure Licensor patent, trademark, service mark or copyright notices. (e) You agree that the Licensed Works will not be shipped, transferred or exported into any other country, or used in any manner prohibited by any government agency or any export laws, restrictions or regulations. (f) You may not publish or distribute in any form of electronic or printed communication the materials within or otherwise related to Licensed Works, including but not limited to the object code, documentation, help files, examples, and benchmarks. TERM: This Agreement is in effect until terminated. You can terminate this Agreement at any time by simply uninstalling the Licensed Works and destroying all copies of it. Upon the termination, you agree to uninstall the Licensed Works and return or destroy all copies of it, any accompanying documentation, and all associated materials. SOFTWARE INSTALLATION: Components bundled into the software may report to Licensor and/or its affiliates the installation status of certain marketing offers and also generalized installation information, such as language preferences and operating system version, to assist Licensor in its products development. No personal information will be communicated to Licensor and/or its affiliates during this process. Licensor reserves the right to install some additional components using its check/update system. These components could include some commercial solutions, commercial homepage manager,commercial messenger and could modify some of your network settings. WARRANTIES AND DISCLAIMER: EXCEPT AS EXPRESSLY PROVIDED OTHERWISE IN A WRITTEN AGREEMENT BETWEEN YOU AND LICENSOR, THE LICENSED WORKS ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE OR THE WARRANTY OF NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, LICENSOR TAKES NO WARRANTY THAT (1) THE LICENSED WORKS WILL MEET ALL OF YOUR REQUIREMENTS, (2) THE USE OF THE LICENSED WORKS WILL BE ABSOLUTELY UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE,(3) THE RESULTS THAT COULD BE OBTAINED FROM THE USE OF THE LICENSED WORKS WILL BE ACCURATE AND/OR RELIABLE, (4) THE QUALITY OF THE LICENSED WORKS WILL MEET ALL OF YOUR EXPECTATIONS, (5) ANY ERROR IN THE LICENSED WORKS WILL BE CORRECTED, AND/OR (6) YOU CAN USE, PRACTICE, EXECUTE, OR ACCESS THE LICENSED WORKS WITHOUT VIOLATING THE INTELLECTUAL PROPERTY RIGHTS OF OTHERS. SOME STATES OR JURISDICTIONS DOES NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES OR LIMITATIONS ON HOW LONG THE IMPLIED WARRANTY COULD LAST, SO THE ABOVE LIMITATIONS COULD NOT APPLY TO YOU. IF CALIFORNIA LAW IS NOT HELD TO APPLY TO THE AGREEMENT FOR ANY REASON, THEN IN JURISDICTIONS WHERE WARRANTIES, GUARANTEES, REPRESENTATIONS, AND/OR CONDITIONS OF ANY TYPE COULD NOT BE DISCLAIMED, ANY SUCH WARRANTY, GUARANTEE, REPRESENTATION AND/OR WARRANTY IS: (1) HEREBY LIMITED TO A PERIOD OF EITHER (A) THIRTY (30) DAYS FROM THE DATE OF INSTALLING THE PACKAGE CONTAINING THE LICENSED WORKS OR (B) THE SHORTEST PERIOD ALLOWED BY THE LAW IN THE APPLICABLE JURISDICTION IF A THIRTY (30) DAY LIMITATION WOULD BE UNENFORCEABLE; AND (2) LICENSOR'S SOLE LIABILITY FOR ANY BREACH OF ANY SUCH WARRANTY, GUARANTEE, REPRESENTATION, AND/OR CONDITION SHALL BE TO PROVIDE YOU WITH A BRAND NEW COPY OF THE LICENSED WORKS. IN NO EVENT SHALL LICENSOR OR ITS SUPPLIERS AND AFFILIATES BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY SPECIAL, INCIDENTAL, INDIRECT OR CONSEQUENTIAL DAMAGES OF ANY KIND, OR ANY DAMAGES WHATSOEVER, INCLUDING BUT NOT LIMITED TO THOSE RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER OR NOT LICENSOR HAD BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, AND ON ANY THEORY OF LIABILITY, ARISING OUT OF OR IN CONNECTION WITH THE USE OF THE LICENSED WORKS. SOME JURISDICTIONS PROHIBIT THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, SO THE ABOVE LIMITATIONS COULD NOT APPLY TO YOU. THESE LIMITATIONS SHALL APPLY NOTWITHSTANDING ANY FAILURE OF ESSENTIAL PURPOSE OF ANY KIND OF LIMITED REMEDY. SEVERABILITY: In the event when any provision of this License Agreement is found to be invalid, illegal or unenforceable, the validity, legality and enforceability of any of remaining provisions shall not in any way be affected or impaired and a valid, legal and enforceable provision of similar intent and economic impact shall be substituted therefore. ENTIRE AGREEMENT: This License Agreement sets forth the entire understanding and agreement between Licensor and You, supersedes all prior agreements, whether written or oral, with respect to the software, and may be amended or modified only in a writing signed by both parties. If you accept the terms of the agreement, click I Agree to continue. You must accept the agreement to install VideoKey.  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

VideoKey Setup 

&Yes &No Are you sure you want to quit VideoKey Setup?  

2.a) stormcodec4117.exe - Registry Activities

 

- Registry Values Modified:

 

Key

Name

New Value

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d14d83ce-7d74-11dc-97e2-806d6172696f}\ 

BaseClass 

Drive 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d14d83cf-7d74-11dc-97e2-806d6172696f}\ 

BaseClass 

Drive 


 

- Registry Values Read:

 

Key

Name

Value

Times

HKLM\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\INPROCSERVER32 

 

%SystemRoot%\system32\SHELL32.dll 

HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9} 

DriveMask 

32 

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion 

CurrentVersion 

5.1 

HKLM\Software\Microsoft\CTF\SystemShared 

CUAS 

HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM 

Ime File 

msctfime.ime 

HKLM\Software\Microsoft\Windows\CurrentVersion 

ProgramFilesDir 

C:\Program Files 

HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName 

ComputerName 

USER 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\ 

Data 

0x000000005c005c003f005c0049004400450023004300640052006f006d00 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\ 

Generation 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\ 

Data 

0x000000005c005c003f005c00530054004f00520041004700450023005600 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\ 

Generation 

2.b) stormcodec4117.exe - File Activities

 

- Files Deleted:

 

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\freebsd.exe

C:\DOCUME~1\user\LOCALS~1\Temp\freebsd.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\linux

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\ns4.tmp

C:\DOCUME~1\user\LOCALS~1\Temp\nsz1.tmp


 

- Files Created:

 

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\freebsd.exe

C:\DOCUME~1\user\LOCALS~1\Temp\freebsd.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\linux

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\dcryptdll.dll

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\modern-header.bmp

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\nsExec.dll

\Device\NamedPipe\Win32Pipes.00000644.00000001

\Device\NamedPipe\Win32Pipes.00000644.00000002


 

- Files Read:

 

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\freebsd.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\linux

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe.dat

C:\DOCUME~1\user\LOCALS~1\Temp\nsv2.tmp

C:\WINDOWS\win.ini

C:\stormcodec4117.exe

PIPE\lsarpc


 

- Files Modified:

 

C:\DOCUME~1\user\LOCALS~1\Temp\nsv2.tmp

MountPointManager

PIPE\lsarpc


 

- Directories Created:

 

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp


 

- File System Control Communication:

 

File

Control Code

Times

PIPE\lsarpc 

0x0011C017 

\Device\NamedPipe\Win32Pipes.00000644.00000001 

0x0011400C 

24 


 

- Device Control Communication:

 

File

Control Code

Times

IDE#CdRomQEMU_QEMU_CD-ROM________________________0.9.____#4d51303030302033202020202020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 

0x004D0008 

MountPointManager 

0x006D0008 

STORAGE#Volume#1&30a96598&0&Signature95619561Offset7E00Length13F291800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 

0x004D0008 

MountPointManager 

0x006D0034 

WMIDataDevice 

0x00228144 


 

- Memory Mapped Files:

 

File Name

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\dcryptdll.dll

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\modern-header.bmp

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\ns4.tmp

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\nsExec.dll

C:\WINDOWS\system32\Msimtf.dll

C:\WINDOWS\system32\rpcss.dll

2.c) stormcodec4117.exe - Process Activities

 

- Processes Created:

 

Executable

Command Line

 

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe 

 

"C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\ns4.tmp" C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe 


 

- Processes Killed:

 

C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\ns4.tmp


 

- Thread Overview:

 

Time

Number of threads

After 221 seconds

After 228 seconds

2.d) stormcodec4117.exe - Other Activities

 

- Mutexes Created:

 

CTF.TimListCache.FMPDefaultS-1-5-21-1229272821-1004336348-527237240-1003MUTEX.DefaultS-1-5-21-1229272821-1004336348-527237240-1003

MSCTF.Shared.MUTEX.AN

MSCTF.Shared.MUTEX.INB


 

- Keyboard Keys Monitored:

 

Virtual Key Code

Times

VK_SHIFT (16) 

VK_LBUTTON (1) 

VK_RBUTTON (2) 

VK_MBUTTON (4) 

3. services.exe

 

- General information about this executable

 

Analysis Reason:

NtConnectPort(\RPC Control\ntsvcs was called. 

Filename:

services.exe 

MD5:

c6ce6eec82f187615d1002bb3bb50ed4 

SHA-1:

b958912d139cb8dbfeeacdd38ba048c4f452174e 

File Size:

108032 Bytes

Command Line:

C:\WINDOWS\system32\services.exe 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\SCESRV.dll 

0x758E0000 

0x00050000 

C:\WINDOWS\system32\AUTHZ.dll 

0x776C0000 

0x00011000 

C:\WINDOWS\system32\umpnpmgr.dll 

0x7DBA0000 

0x00021000 

C:\WINDOWS\system32\WINSTA.dll 

0x76360000 

0x00010000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

C:\WINDOWS\system32\NCObjAPI.DLL 

0x5F770000 

0x0000C000 

C:\WINDOWS\system32\MSVCP60.dll 

0x76080000 

0x00065000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 

C:\WINDOWS\system32\eventlog.dll 

0x77B70000 

0x00011000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\PSAPI.DLL 

0x76BF0000 

0x0000B000 

C:\WINDOWS\system32\wtsapi32.dll 

0x76F50000 

0x00008000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x007B0000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

3.a) services.exe - Registry Activities

 

- Registry Keys Created Or Opened:

 

HKLM\SOFTWARE\CLASSES

3.b) services.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 

3.c) services.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 163 seconds

After 168 seconds

4. notepad.exe

 

- General information about this executable

 

Analysis Reason:

Started by stormcodec4117.exe 

Filename:

notepad.exe 

Command Line:

C:\DOCUME~1\user\LOCALS~1\Temp\notepad.exe 

Process-status at analysis end:

dead 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\user32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

4.a) notepad.exe - Registry Activities

 

- Registry Values Modified:

 

Key

Name

New Value

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874} 

DhcpNameServer 

85.255.116.71,85.255.112.63 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874} 

NameServer 

85.255.116.71,85.255.112.63 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C7C75F97-CEE5-40F7-8B3F-AC3137A65E2A} 

DhcpNameServer 

85.255.116.71,85.255.112.63 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C7C75F97-CEE5-40F7-8B3F-AC3137A65E2A} 

NameServer 

85.255.116.71,85.255.112.63 

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 

Common AppData 

C:\Documents and Settings\All Users\Application Data 

HKLM\System\CurrentControlSet\Services\Tcpip\Parameters 

DhcpNameServer 

85.255.116.71 85.255.112.63 

HKLM\System\CurrentControlSet\Services\Tcpip\Parameters 

NameServer 

85.255.116.71 85.255.112.63 


 

- Registry Values Read:

 

Key

Name

Value

Times

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp 

IpConfig 

0x540063007000690070005c0050006100720061006d006500740065007200 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{B2B51064-BBF5-4528-B62B-E6D62A782874} 

IpConfig 

0x540063007000690070005c0050006100720061006d006500740065007200 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874} 

NameServer 

192.168.0.1 

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders 

Common AppData 

%ALLUSERSPROFILE%\Application Data 

5. ns4.tmp

 

- General information about this executable

 

Analysis Reason:

Started by stormcodec4117.exe 

Filename:

ns4.tmp 

Command Line:

"C:\DOCUME~1\user\LOCALS~1\Temp\nsx3.tmp\ns4.tmp" C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe 

Process-status at analysis end:

dead 

Exit Code:

-1 


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

5.a) ns4.tmp - Process Activities

 

- Processes Created:

 

Executable

Command Line

 

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe 

6. calc.exe

 

- General information about this executable

 

Analysis Reason:

Started by ns4.tmp 

Filename:

calc.exe 

MD5:

1b437bbb5e8ca34295e8093792aea9b9 

SHA-1:

bc33110a851cdb262504cdbeace9217025db495f 

File Size:

61952 Bytes

Command Line:

C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\user32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00870000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

6.a) calc.exe - Registry Activities

 

- Registry Values Modified:

 

Key

Name

New Value

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon 

System 

kdptq.exe 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 

Cache 

C:\Documents and Settings\user\Local Settings\Temporary Internet Files 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 

Cookies 

C:\Documents and Settings\user\Cookies 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders 

History 

C:\Documents and Settings\user\Local Settings\History 


 

- Registry Values Read:

 

Key

Name

Value

Times

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content 

PerUserItem 

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies 

PerUserItem 

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History 

PerUserItem 

HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName 

ComputerName 

USER 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url1 

http://www.adobe.com/products/acrobat/readstep2.html 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url10 

https://www.google.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url11 

https://www.gmx.at/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url12 

http://www.icq.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url13 

http://www.google.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url14 

http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url2 

http://www.adobe.com/products 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url3 

http://java.sun.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url4 

http://www.google.at/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url5 

http://www.adobe.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url6 

http://www.ccleaner.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url7 

https://www.amazon.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url8 

https://wumt.westernunion.com/info/selectCountry.asp 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Internet Explorer\TypedURLs 

url9 

http://www.westernunion.com/ 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders 

Cache 

%USERPROFILE%\Local Settings\Temporary Internet Files 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders 

Cookies 

%USERPROFILE%\Cookies 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders 

History 

%USERPROFILE%\Local Settings\History 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache 

Signature 

Client UrlCache MMF Ver 5.2 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content 

CacheLimit 

163410 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content 

CachePrefix 

 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies 

CachePrefix 

Cookie: 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022 

CacheOptions 

11 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022 

CachePath 

%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007101520071022 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022 

CachePrefix 

:2007101520071022:  

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022 

CacheRepair 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029 

CacheOptions 

11 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029 

CachePath 

%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007102220071029 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029 

CachePrefix 

:2007102220071029:  

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029 

CacheRepair 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102 

CacheOptions 

11 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102 

CachePath 

%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007110120071102 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102 

CachePrefix 

:2007110120071102:  

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102 

CacheRepair 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData 

CacheLimit 

1000 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData 

CacheOptions 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData 

CachePath 

%USERPROFILE%\UserData 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData 

CachePrefix 

UserData 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData 

CacheRepair 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat 

CacheOptions 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat 

CachePath 

%USERPROFILE%\Local Settings\Application Data\Microsoft\Feeds Cache 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat 

CachePrefix 

feedplat: 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat 

CacheRepair 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History 

CacheLimit 

8192 

HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History 

CachePrefix 

Visited: 

6.b) calc.exe - File Activities

 

- Files Read:

 

PIPE\lsarpc


 

- Files Modified:

 

PIPE\lsarpc


 

- File System Control Communication:

 

File

Control Code

Times

PIPE\lsarpc 

0x0011C017 

12 


 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 


 

- Memory Mapped Files:

 

File Name

C:\WINDOWS\system32\kernel32.dll

C:\Documents and Settings\user\Cookies\index.dat

C:\Documents and Settings\user\Local Settings\History\History.IE5\index.dat

C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\index.dat

6.c) calc.exe - Process Activities

 

- Remote Threads Created:

 

Affected Process

C:\WINDOWS\system32\csrss.exe


 

- Thread Overview:

 

Time

Number of threads

After 69 seconds


 

- Foreign Memory Regions Read:

 

Process: C:\WINDOWS\system32\alg.exe

Process: C:\WINDOWS\system32\csrss.exe

Process: C:\WINDOWS\system32\ftvmdmsrv.exe

Process: C:\WINDOWS\system32\lsass.exe

Process: C:\WINDOWS\system32\services.exe

Process: C:\WINDOWS\system32\smss.exe

Process: C:\WINDOWS\system32\spoolsv.exe

Process: C:\WINDOWS\system32\svchost.exe

Process: C:\WINDOWS\system32\winlogon.exe

7. csrss.exe

 

- General information about this executable

 

Analysis Reason:

calc.exe injected a remote thread into this process 

Filename:

csrss.exe 

Command Line:

C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\CSRSRV.dll 

0x75B40000 

0x0000B000 

C:\WINDOWS\system32\basesrv.dll 

0x75B50000 

0x00010000 

C:\WINDOWS\system32\winsrv.dll 

0x75B60000 

0x0004B000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\KERNEL32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\sxs.dll 

0x75E90000 

0x000B0000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x01320000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

7.a) csrss.exe - Registry Activities

 

- Registry Keys Created Or Opened:

 

HKLM\SOFTWARE\CLASSES


 

- Registry Values Read:

 

Key

Name

Value

Times

HKLM\SYSTEM\SETUP 

SystemSetupInProgress 

94 

HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS 

HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL 

7.b) csrss.exe - File Activities

 

- Files Read:

 

C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03.Manifest

C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2982.Policy


 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 

7.c) csrss.exe - Process Activities

 

- Remote Threads Created:

 

Affected Process

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\lsass.exe

C:\exec\popupKiller.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\stormcodec4117.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe


 

- Thread Overview:

 

Time

Number of threads

After 153 seconds


 

- Foreign Memory Regions Read:

 

Process: C:\DOCUME~1\user\LOCALS~1\Temp\calc.exe

Process: C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

Process: C:\WINDOWS\system32\alg.exe

Process: C:\WINDOWS\system32\csrss.exe

Process: C:\WINDOWS\system32\ftvmdmsrv.exe

Process: C:\WINDOWS\system32\lsass.exe

Process: C:\WINDOWS\system32\services.exe

Process: C:\WINDOWS\system32\smss.exe

Process: C:\WINDOWS\system32\spoolsv.exe

Process: C:\WINDOWS\system32\svchost.exe

Process: C:\WINDOWS\system32\winlogon.exe

Process: C:\exec\popupKiller.exe

Process: C:\stormcodec4117.exe

7.d) csrss.exe - Other Activities

 

- Windows SEH exceptions:

 

Description

Times

Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x75b5a753 

8. winlogon.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

winlogon.exe 

Command Line:

winlogon.exe 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\AUTHZ.dll 

0x776C0000 

0x00011000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\CRYPT32.dll 

0x77A80000 

0x00094000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\MSASN1.dll 

0x77B20000 

0x00012000 

C:\WINDOWS\system32\NDdeApi.dll 

0x75940000 

0x00008000 

C:\WINDOWS\system32\PROFMAP.dll 

0x75930000 

0x0000A000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\PSAPI.DLL 

0x76BF0000 

0x0000B000 

C:\WINDOWS\system32\REGAPI.dll 

0x76BC0000 

0x0000F000 

C:\WINDOWS\system32\SETUPAPI.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\WINSTA.dll 

0x76360000 

0x00010000 

C:\WINDOWS\system32\WINTRUST.dll 

0x76C30000 

0x0002E000 

C:\WINDOWS\system32\IMAGEHLP.dll 

0x76C90000 

0x00028000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\system32\MSGINA.dll 

0x75970000 

0x000F7000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\COMCTL32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\ODBC32.dll 

0x74320000 

0x0003D000 

C:\WINDOWS\system32\comdlg32.dll 

0x763B0000 

0x00049000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\odbcint.dll 

0x20000000 

0x00017000 

C:\WINDOWS\system32\SHSVCS.dll 

0x776E0000 

0x00023000 

C:\WINDOWS\system32\sfc.dll 

0x76BB0000 

0x00005000 

C:\WINDOWS\system32\sfc_os.dll 

0x76C60000 

0x0002A000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 

C:\WINDOWS\system32\msctfime.ime 

0x755C0000 

0x0002E000 

C:\WINDOWS\system32\WINSCARD.DLL 

0x723D0000 

0x0001C000 

C:\WINDOWS\system32\WTSAPI32.dll 

0x76F50000 

0x00008000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\uxtheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\cscdll.dll 

0x76600000 

0x0001D000 

C:\WINDOWS\system32\WlNotify.dll 

0x75950000 

0x0001A000 

C:\WINDOWS\system32\WINSPOOL.DRV 

0x73000000 

0x00026000 

C:\WINDOWS\system32\MPR.dll 

0x71B20000 

0x00012000 

C:\WINDOWS\system32\rsaenh.dll 

0x0FFD0000 

0x00028000 

C:\WINDOWS\system32\SAMLIB.dll 

0x71BF0000 

0x00013000 

C:\WINDOWS\system32\msv1_0.dll 

0x77C70000 

0x00023000 

C:\WINDOWS\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\system32\wldap32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\sxs.dll 

0x75E90000 

0x000B0000 

C:\WINDOWS\system32\cscui.dll 

0x77A20000 

0x00054000 

C:\WINDOWS\system32\MPRAPI.dll 

0x76D40000 

0x00018000 

C:\WINDOWS\system32\ACTIVEDS.dll 

0x77CC0000 

0x00032000 

C:\WINDOWS\system32\adsldpc.dll 

0x76E10000 

0x00025000 

C:\WINDOWS\system32\ATL.DLL 

0x76B20000 

0x00011000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\rtutils.dll 

0x76E80000 

0x0000E000 

C:\WINDOWS\system32\xpsp2res.dll 

0x014B0000 

0x002C5000 

C:\WINDOWS\system32\COMRes.dll 

0x77050000 

0x000C5000 

C:\WINDOWS\system32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\system32\NTMARTA.DLL 

0x77690000 

0x00021000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00B30000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

8.a) winlogon.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 


 

- Memory Mapped Files:

 

File Name

C:\WINDOWS\system32\Msctf.dll

8.b) winlogon.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 157 seconds

After 162 seconds

9. lsass.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

lsass.exe 

MD5:

84885f9b82f4d55c6146ebf6065d75d2 

SHA-1:

6473b34c05bc63eb0d66cad83355e6938cbe97e9 

File Size:

13312 Bytes

Command Line:

C:\WINDOWS\system32\lsass.exe 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\LSASRV.dll 

0x75730000 

0x000B4000 

C:\WINDOWS\system32\MPR.dll 

0x71B20000 

0x00012000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\MSASN1.dll 

0x77B20000 

0x00012000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

C:\WINDOWS\system32\NTDSAPI.dll 

0x767A0000 

0x00013000 

C:\WINDOWS\system32\DNSAPI.dll 

0x76F20000 

0x00027000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\SAMLIB.dll 

0x71BF0000 

0x00013000 

C:\WINDOWS\system32\SAMSRV.dll 

0x74440000 

0x0006A000 

C:\WINDOWS\system32\cryptdll.dll 

0x76790000 

0x0000C000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\msprivs.dll 

0x20000000 

0x0000E000 

C:\WINDOWS\system32\kerberos.dll 

0x71CF0000 

0x0004B000 

C:\WINDOWS\system32\msv1_0.dll 

0x77C70000 

0x00023000 

C:\WINDOWS\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\system32\netlogon.dll 

0x744B0000 

0x00065000 

C:\WINDOWS\system32\w32time.dll 

0x767C0000 

0x0002C000 

C:\WINDOWS\system32\MSVCP60.dll 

0x76080000 

0x00065000 

C:\WINDOWS\system32\schannel.dll 

0x767F0000 

0x00027000 

C:\WINDOWS\system32\CRYPT32.dll 

0x77A80000 

0x00094000 

C:\WINDOWS\system32\wdigest.dll 

0x74380000 

0x0000F000 

C:\WINDOWS\system32\rsaenh.dll 

0x0FFD0000 

0x00028000 

C:\WINDOWS\system32\setupapi.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\system32\scecli.dll 

0x74410000 

0x0002E000 

C:\WINDOWS\system32\ipsecsvc.dll 

0x743E0000 

0x0002F000 

C:\WINDOWS\system32\AUTHZ.dll 

0x776C0000 

0x00011000 

C:\WINDOWS\system32\oakley.DLL 

0x75D90000 

0x000CE000 

C:\WINDOWS\system32\WINIPSEC.DLL 

0x74370000 

0x0000B000 

C:\WINDOWS\system32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\system32\hnetcfg.dll 

0x662B0000 

0x00058000 

C:\WINDOWS\System32\wshtcpip.dll 

0x71A90000 

0x00008000 

C:\WINDOWS\system32\pstorsvc.dll 

0x743A0000 

0x0000B000 

C:\WINDOWS\system32\psbase.dll 

0x743C0000 

0x0001B000 

C:\WINDOWS\system32\dssenh.dll 

0x68100000 

0x00024000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00A10000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

9.a) lsass.exe - Registry Activities

 

- Registry Keys Created Or Opened:

 

HKLM\SOFTWARE\CLASSES

9.b) lsass.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

unnamed file 

0x00228144 

9.c) lsass.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 174 seconds

10. popupKiller.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

popupKiller.exe 

MD5:

b8ccbffde3c450d938921b77edd31e0c 

SHA-1:

a1d5f57a6fb6871d35dd3545d752a43bd0fc4482 

File Size:

183797 Bytes

Command Line:

popupKiller.exe 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\comdlg32.dll 

0x763B0000 

0x00049000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\MPR.dll 

0x71B20000 

0x00012000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\WSOCK32.dll 

0x71AD0000 

0x00009000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\system32\wininet.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\Normaliz.dll 

0x003A0000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\SETUPAPI.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\system32\MSCTF.dll 

0x74720000 

0x0004B000 

C:\WINDOWS\system32\msctfime.ime 

0x755C0000 

0x0002E000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 


 

- SigBuster Output

 

UPX All_Versions SN:1634

10.a) popupKiller.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 181 seconds

11. svchost.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

svchost.exe 

MD5:

8f078ae4ed187aaabc0a305146de6716 

SHA-1:

da0ff4006859a7580aba81f486f692dead2014fe 

File Size:

14336 Bytes

Command Line:

C:\WINDOWS\system32\svchost -k DcomLaunch 

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\NTMARTA.DLL 

0x77690000 

0x00021000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\SAMLIB.dll 

0x71BF0000 

0x00013000 

c:\windows\system32\rpcss.dll 

0x76A80000 

0x00063000 

c:\windows\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

c:\windows\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\xpsp2res.dll 

0x20000000 

0x002C5000 

c:\windows\system32\termsrv.dll 

0x760F0000 

0x00053000 

c:\windows\system32\ICAAPI.dll 

0x74F70000 

0x00006000 

c:\windows\system32\SETUPAPI.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\system32\WINTRUST.dll 

0x76C30000 

0x0002E000 

C:\WINDOWS\system32\CRYPT32.dll 

0x77A80000 

0x00094000 

C:\WINDOWS\system32\MSASN1.dll 

0x77B20000 

0x00012000 

C:\WINDOWS\system32\IMAGEHLP.dll 

0x76C90000 

0x00028000 

c:\windows\system32\AUTHZ.dll 

0x776C0000 

0x00011000 

c:\windows\system32\mstlsapi.dll 

0x75110000 

0x0001F000 

c:\windows\system32\ACTIVEDS.dll 

0x77CC0000 

0x00032000 

c:\windows\system32\adsldpc.dll 

0x76E10000 

0x00025000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

c:\windows\system32\ATL.DLL 

0x76B20000 

0x00011000 

C:\WINDOWS\system32\REGAPI.dll 

0x76BC0000 

0x0000F000 

C:\WINDOWS\system32\rsaenh.dll 

0x0FFD0000 

0x00028000 

C:\WINDOWS\system32\WTSAPI32.dll 

0x76F50000 

0x00008000 

C:\WINDOWS\system32\WINSTA.dll 

0x76360000 

0x00010000 

C:\WINDOWS\system32\msv1_0.dll 

0x77C70000 

0x00023000 

C:\WINDOWS\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\system32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\system32\COMRes.dll 

0x77050000 

0x000C5000 

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00C70000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

11.a) svchost.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 

11.b) svchost.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 185 seconds

After 190 seconds

12. jusched.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

jusched.exe 

MD5:

d4f0f7437327dbaa264338baafb5e5af 

SHA-1:

c668421e98c76af8cd8542e6ca56992d6efe828f 

File Size:

132496 Bytes

Command Line:

"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"  

Process-status at analysis end:

alive 

Exit Code:


 

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\Normaliz.dll 

0x00330000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 


 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

12.a) jusched.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 195 seconds

13. svchost.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

svchost.exe 

MD5:

8f078ae4ed187aaabc0a305146de6716 

SHA-1:

da0ff4006859a7580aba81f486f692dead2014fe 

File Size:

14336 Bytes

Command Line:

C:\WINDOWS\system32\svchost.exe -k NetworkService 

Process-status at analysis end:

alive 

Exit Code:

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

c:\windows\system32\dnsrslvr.dll 

0x76770000 

0x0000D000 

c:\windows\system32\DNSAPI.dll 

0x76F20000 

0x00027000 

c:\windows\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

c:\windows\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

c:\windows\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\system32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\system32\hnetcfg.dll 

0x662B0000 

0x00058000 

C:\WINDOWS\System32\wshtcpip.dll 

0x71A90000 

0x00008000 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00730000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

13.a) svchost.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 

13.b) svchost.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 197 seconds

After 203 seconds

14. svchost.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

svchost.exe 

MD5:

8f078ae4ed187aaabc0a305146de6716 

SHA-1:

da0ff4006859a7580aba81f486f692dead2014fe 

File Size:

14336 Bytes

Command Line:

C:\WINDOWS\system32\svchost -k rpcss 

Process-status at analysis end:

alive 

Exit Code:

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

c:\windows\system32\rpcss.dll 

0x76A80000 

0x00063000 

c:\windows\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

c:\windows\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\xpsp2res.dll 

0x20000000 

0x002C5000 

C:\WINDOWS\system32\rsaenh.dll 

0x0FFD0000 

0x00028000 

C:\WINDOWS\system32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\system32\hnetcfg.dll 

0x662B0000 

0x00058000 

C:\WINDOWS\System32\wshtcpip.dll 

0x71A90000 

0x00008000 

C:\WINDOWS\system32\DNSAPI.dll 

0x76F20000 

0x00027000 

C:\WINDOWS\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\System32\winrnr.dll 

0x76FB0000 

0x00008000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\rasadhlp.dll 

0x76FC0000 

0x00006000 

C:\WINDOWS\system32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\system32\COMRes.dll 

0x77050000 

0x000C5000 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00840000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

14.a) svchost.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

WMIDataDevice 

0x00228144 

14.b) svchost.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 207 seconds

After 215 seconds

15. svchost.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

svchost.exe 

MD5:

8f078ae4ed187aaabc0a305146de6716 

SHA-1:

da0ff4006859a7580aba81f486f692dead2014fe 

File Size:

14336 Bytes

Command Line:

C:\WINDOWS\System32\svchost.exe -k netsvcs 

Process-status at analysis end:

alive 

Exit Code:

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\System32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\System32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\System32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\System32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\System32\NTMARTA.DLL 

0x77690000 

0x00021000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\System32\SAMLIB.dll 

0x71BF0000 

0x00013000 

C:\WINDOWS\System32\xpsp2res.dll 

0x20000000 

0x002C5000 

c:\windows\system32\shsvcs.dll 

0x776E0000 

0x00023000 

C:\WINDOWS\System32\WINSTA.dll 

0x76360000 

0x00010000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

c:\windows\system32\dhcpcsvc.dll 

0x76D80000 

0x0001E000 

c:\windows\system32\DNSAPI.dll 

0x76F20000 

0x00027000 

c:\windows\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

c:\windows\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

c:\windows\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

C:\WINDOWS\System32\rsaenh.dll 

0x0FFD0000 

0x00028000 

c:\windows\system32\wzcsvc.dll 

0x77620000 

0x0006E000 

c:\windows\system32\rtutils.dll 

0x76E80000 

0x0000E000 

c:\windows\system32\WMI.dll 

0x76D30000 

0x00004000 

C:\WINDOWS\system32\CRYPT32.dll 

0x77A80000 

0x00094000 

C:\WINDOWS\system32\MSASN1.dll 

0x77B20000 

0x00012000 

c:\windows\system32\WTSAPI32.dll 

0x76F50000 

0x00008000 

c:\windows\system32\ESENT.dll 

0x606B0000 

0x0010D000 

c:\windows\system32\ATL.DLL 

0x76B20000 

0x00011000 

C:\WINDOWS\System32\rastls.dll 

0x76B70000 

0x0001F000 

C:\WINDOWS\system32\CRYPTUI.dll 

0x754D0000 

0x00080000 

C:\WINDOWS\system32\WINTRUST.dll 

0x76C30000 

0x0002E000 

C:\WINDOWS\system32\IMAGEHLP.dll 

0x76C90000 

0x00028000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\Normaliz.dll 

0x00AD0000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\System32\MPRAPI.dll 

0x76D40000 

0x00018000 

C:\WINDOWS\System32\ACTIVEDS.dll 

0x77CC0000 

0x00032000 

C:\WINDOWS\System32\adsldpc.dll 

0x76E10000 

0x00025000 

C:\WINDOWS\System32\SETUPAPI.dll 

0x77920000 

0x000F3000 

C:\WINDOWS\System32\RASAPI32.dll 

0x76EE0000 

0x0003C000 

C:\WINDOWS\System32\rasman.dll 

0x76E90000 

0x00012000 

C:\WINDOWS\System32\TAPI32.dll 

0x76EB0000 

0x0002F000 

C:\WINDOWS\System32\SCHANNEL.dll 

0x767F0000 

0x00027000 

C:\WINDOWS\System32\WinSCard.dll 

0x723D0000 

0x0001C000 

C:\WINDOWS\System32\raschap.dll 

0x76BD0000 

0x00014000 

C:\WINDOWS\system32\msv1_0.dll 

0x77C70000 

0x00023000 

C:\WINDOWS\System32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\System32\COMRes.dll 

0x77050000 

0x000C5000 

c:\windows\system32\schedsvc.dll 

0x77300000 

0x00032000 

c:\windows\system32\NTDSAPI.dll 

0x767A0000 

0x00013000 

C:\WINDOWS\System32\MSIDLE.DLL 

0x74F50000 

0x00005000 

c:\windows\system32\audiosrv.dll 

0x708B0000 

0x0000D000 

c:\windows\system32\wkssvc.dll 

0x76E40000 

0x00023000 

c:\windows\system32\cryptsvc.dll 

0x76CE0000 

0x00012000 

c:\windows\system32\certcli.dll 

0x77B90000 

0x00032000 

c:\windows\system32\dmserver.dll 

0x74F90000 

0x00009000 

c:\windows\system32\ersvc.dll 

0x74F80000 

0x00009000 

c:\windows\system32\es.dll 

0x77710000 

0x00041000 

c:\windows\pchealth\helpctr\binaries\pchsvc.dll 

0x74F40000 

0x0000C000 

c:\windows\system32\srvsvc.dll 

0x75090000 

0x0001A000 

C:\WINDOWS\System32\HNETCFG.DLL 

0x662B0000 

0x00058000 

c:\windows\system32\netman.dll 

0x77D00000 

0x00033000 

c:\windows\system32\netshell.dll 

0x76400000 

0x001A6000 

c:\windows\system32\credui.dll 

0x76C00000 

0x0002E000 

c:\windows\system32\WZCSAPI.DLL 

0x73030000 

0x00010000 

c:\windows\system32\seclogon.dll 

0x73D20000 

0x00008000 

c:\windows\system32\sens.dll 

0x722D0000 

0x0000D000 

c:\windows\system32\srsvc.dll 

0x751A0000 

0x0002E000 

c:\windows\system32\POWRPROF.dll 

0x74AD0000 

0x00008000 

c:\windows\system32\trkwks.dll 

0x75070000 

0x00019000 

c:\windows\system32\w32time.dll 

0x767C0000 

0x0002C000 

c:\windows\system32\MSVCP60.dll 

0x76080000 

0x00065000 

c:\windows\system32\wbem\wmisvc.dll 

0x59490000 

0x00028000 

C:\WINDOWS\system32\VSSAPI.DLL 

0x753E0000 

0x0006D000 

C:\WINDOWS\system32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\System32\wshtcpip.dll 

0x71A90000 

0x00008000 

c:\windows\system32\wuauserv.dll 

0x50000000 

0x00005000 

C:\WINDOWS\system32\wuaueng.dll 

0x50040000 

0x001A2000 

C:\WINDOWS\System32\WINSPOOL.DRV 

0x73000000 

0x00026000 

C:\WINDOWS\System32\WINHTTP.dll 

0x4D4F0000 

0x00058000 

C:\WINDOWS\System32\Cabinet.dll 

0x75150000 

0x00014000 

C:\WINDOWS\System32\mspatcha.dll 

0x600A0000 

0x0000B000 

c:\windows\system32\browser.dll 

0x76DA0000 

0x00015000 

c:\windows\system32\wscsvc.dll 

0x4C0A0000 

0x00017000 

c:\windows\system32\msi.dll 

0x7D1E0000 

0x002BE000 

C:\WINDOWS\system32\wbem\wbemcomn.dll 

0x75290000 

0x00037000 

C:\WINDOWS\System32\Wbem\wbemcore.dll 

0x762C0000 

0x00085000 

C:\WINDOWS\System32\Wbem\esscli.dll 

0x75310000 

0x0003F000 

C:\WINDOWS\System32\Wbem\FastProx.dll 

0x75690000 

0x00076000 

C:\WINDOWS\system32\wbem\wmiutils.dll 

0x75020000 

0x0001B000 

C:\WINDOWS\system32\wbem\repdrvfs.dll 

0x75200000 

0x0002E000 

C:\WINDOWS\System32\SXS.DLL 

0x75E90000 

0x000B0000 

C:\WINDOWS\system32\comsvcs.dll 

0x76620000 

0x0013C000 

C:\WINDOWS\system32\colbact.DLL 

0x75130000 

0x00014000 

C:\WINDOWS\system32\MTXCLU.DLL 

0x750F0000 

0x00013000 

C:\WINDOWS\system32\WSOCK32.dll 

0x71AD0000 

0x00009000 

C:\WINDOWS\System32\CLUSAPI.DLL 

0x76D10000 

0x00011000 

C:\WINDOWS\System32\RESUTILS.DLL 

0x750B0000 

0x00012000 

C:\WINDOWS\system32\wbem\wmiprvsd.dll 

0x597F0000 

0x0006D000 

C:\WINDOWS\system32\NCObjAPI.DLL 

0x5F770000 

0x0000C000 

C:\WINDOWS\System32\winrnr.dll 

0x76FB0000 

0x00008000 

C:\WINDOWS\system32\wbem\wbemess.dll 

0x75390000 

0x00046000 

c:\windows\system32\ipnathlp.dll 

0x66460000 

0x00055000 

c:\windows\system32\AUTHZ.dll 

0x776C0000 

0x00011000 

C:\WINDOWS\System32\sfc.dll 

0x76BB0000 

0x00005000 

C:\WINDOWS\System32\sfc_os.dll 

0x76C60000 

0x0002A000 

C:\WINDOWS\system32\wbem\ncprov.dll 

0x5F740000 

0x0000E000 

C:\WINDOWS\System32\rasadhlp.dll 

0x76FC0000 

0x00006000 

C:\WINDOWS\system32\upnp.dll 

0x76DE0000 

0x00023000 

C:\WINDOWS\system32\SSDPAPI.dll 

0x74F00000 

0x0000C000 

C:\WINDOWS\system32\msxml3.dll 

0x74980000 

0x00113000 

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\Apphelp.dll 

0x77B40000 

0x00022000 

C:\WINDOWS\System32\RASDLG.dll 

0x768D0000 

0x000A4000 

C:\WINDOWS\system32\wups2.dll 

0x50E60000 

0x0000C000 

C:\WINDOWS\system32\wbem\wbemsvc.dll 

0x74ED0000 

0x0000E000 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\System32\psapi.dll 

0x76BF0000 

0x0000B000 

15.a) svchost.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

C:\Endpoint 

AFD_SELECT (0x00012024) 

15.b) svchost.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 219 seconds

16. svchost.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

svchost.exe 

MD5:

8f078ae4ed187aaabc0a305146de6716 

SHA-1:

da0ff4006859a7580aba81f486f692dead2014fe 

File Size:

14336 Bytes

Command Line:

C:\WINDOWS\system32\svchost.exe -k LocalService 

Process-status at analysis end:

alive 

Exit Code:

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\NTMARTA.DLL 

0x77690000 

0x00021000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\SAMLIB.dll 

0x71BF0000 

0x00013000 

C:\WINDOWS\system32\xpsp2res.dll 

0x20000000 

0x002C5000 

c:\windows\system32\lmhsvc.dll 

0x74C40000 

0x00006000 

c:\windows\system32\iphlpapi.dll 

0x76D60000 

0x00019000 

c:\windows\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

c:\windows\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

c:\windows\system32\webclnt.dll 

0x5A6E0000 

0x00015000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

C:\WINDOWS\system32\Normaliz.dll 

0x00670000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

c:\windows\system32\alrsvc.dll 

0x70F80000 

0x00008000 

C:\WINDOWS\system32\NETAPI32.dll 

0x5B860000 

0x00054000 

c:\windows\system32\regsvc.dll 

0x76AF0000 

0x00012000 

c:\windows\system32\ssdpsrv.dll 

0x765E0000 

0x00014000 

C:\WINDOWS\system32\hnetcfg.dll 

0x662B0000 

0x00058000 

C:\WINDOWS\system32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\system32\COMRes.dll 

0x77050000 

0x000C5000 

C:\WINDOWS\system32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\System32\wshtcpip.dll 

0x71A90000 

0x00008000 

C:\WINDOWS\system32\rsaenh.dll 

0x0FFD0000 

0x00028000 

C:\WINDOWS\system32\httpapi.dll 

0x67570000 

0x00009000 

C:\WINDOWS\system32\WINHTTP.dll 

0x4D4F0000 

0x00058000 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\urlmon.dll 

0x42CF0000 

0x00124000 

C:\WINDOWS\system32\psapi.dll 

0x76BF0000 

0x0000B000 

16.a) svchost.exe - Process Activities

 

- Thread Overview:

 

Time

Number of threads

After 234 seconds

17. spoolsv.exe

 

- General information about this executable

 

Analysis Reason:

csrss.exe injected a remote thread into this process 

Filename:

spoolsv.exe 

MD5:

da81ec57acd4cdc3d4c51cf3d409af9f 

SHA-1:

7047ed8bd91f3e57972483feaa56e3499cd8c668 

File Size:

57856 Bytes

Command Line:

C:\WINDOWS\system32\spoolsv.exe 

Process-status at analysis end:

alive 

Exit Code:

- Load-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\ntdll.dll 

0x7C900000 

0x000B0000 

C:\WINDOWS\system32\kernel32.dll 

0x7C800000 

0x000F5000 

C:\WINDOWS\system32\ADVAPI32.dll 

0x77DD0000 

0x0009B000 

C:\WINDOWS\system32\RPCRT4.dll 

0x77E70000 

0x00092000 

C:\WINDOWS\system32\Secur32.dll 

0x77FE0000 

0x00011000 

C:\WINDOWS\system32\GDI32.dll 

0x77F10000 

0x00047000 

C:\WINDOWS\system32\USER32.dll 

0x7E410000 

0x00090000 

C:\WINDOWS\system32\msvcrt.dll 

0x77C10000 

0x00058000 

C:\WINDOWS\system32\ShimEng.dll 

0x5CB70000 

0x00026000 

C:\WINDOWS\AppPatch\AcGenral.DLL 

0x6F880000 

0x001CA000 

C:\WINDOWS\system32\WINMM.dll 

0x76B40000 

0x0002D000 

C:\WINDOWS\system32\ole32.dll 

0x774E0000 

0x0013D000 

C:\WINDOWS\system32\OLEAUT32.dll 

0x77120000 

0x0008B000 

C:\WINDOWS\system32\MSACM32.dll 

0x77BE0000 

0x00015000 

C:\WINDOWS\system32\VERSION.dll 

0x77C00000 

0x00008000 

C:\WINDOWS\system32\SHELL32.dll 

0x7C9C0000 

0x00815000 

C:\WINDOWS\system32\SHLWAPI.dll 

0x77F60000 

0x00076000 

C:\WINDOWS\system32\USERENV.dll 

0x769C0000 

0x000B3000 

C:\WINDOWS\system32\UxTheme.dll 

0x5AD70000 

0x00038000 

C:\WINDOWS\system32\IMM32.DLL 

0x76390000 

0x0001D000 

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 

0x773D0000 

0x00103000 

C:\WINDOWS\system32\comctl32.dll 

0x5D090000 

0x0009A000 

C:\WINDOWS\system32\SPOOLSS.DLL 

0x742E0000 

0x00015000 

C:\WINDOWS\system32\WS2_32.dll 

0x71AB0000 

0x00017000 

C:\WINDOWS\system32\WS2HELP.dll 

0x71AA0000 

0x00008000 

C:\WINDOWS\system32\DNSAPI.dll 

0x76F20000 

0x00027000 

C:\WINDOWS\system32\rasadhlp.dll 

0x76FC0000 

0x00006000 

C:\WINDOWS\system32\localspl.dll 

0x75BB0000 

0x00056000 

C:\WINDOWS\system32\sfc_os.dll 

0x76C60000 

0x0002A000 

C:\WINDOWS\system32\WINTRUST.dll 

0x76C30000 

0x0002E000 

C:\WINDOWS\system32\CRYPT32.dll 

0x77A80000 

0x00094000 

C:\WINDOWS\system32\MSASN1.dll 

0x77B20000 

0x00012000 

C:\WINDOWS\system32\IMAGEHLP.dll 

0x76C90000 

0x00028000 

C:\WINDOWS\system32\winspool.drv 

0x73000000 

0x00026000 

C:\WINDOWS\system32\netapi32.dll 

0x5B860000 

0x00054000 

C:\WINDOWS\system32\cnbjmon.dll 

0x742A0000 

0x0000E000 

C:\WINDOWS\system32\mdimon.dll 

0x008F0000 

0x00008000 

C:\WINDOWS\system32\msi.dll 

0x7D1E0000 

0x002BE000 

C:\WINDOWS\system32\pjlmon.dll 

0x74280000 

0x00007000 

C:\WINDOWS\system32\tcpmon.dll 

0x72400000 

0x0000E000 

C:\WINDOWS\system32\usbmon.dll 

0x723F0000 

0x00007000 

C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll 

0x00900000 

0x00008000 

C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll 

0x00910000 

0x0000A000 

C:\WINDOWS\System32\mswsock.dll 

0x71A50000 

0x0003F000 

C:\WINDOWS\System32\winrnr.dll 

0x76FB0000 

0x00008000 

C:\WINDOWS\system32\WLDAP32.dll 

0x76F60000 

0x0002C000 

C:\WINDOWS\system32\win32spl.dll 

0x75C10000 

0x00023000 

C:\WINDOWS\system32\NETRAP.dll 

0x71C80000 

0x00007000 

C:\WINDOWS\system32\NTDSAPI.dll 

0x767A0000 

0x00013000 

C:\WINDOWS\system32\CLBCATQ.DLL 

0x76FD0000 

0x0007F000 

C:\WINDOWS\system32\COMRes.dll 

0x77050000 

0x000C5000 

C:\WINDOWS\system32\inetpp.dll 

0x74300000 

0x00015000 

C:\WINDOWS\system32\xpsp2res.dll 

0x20000000 

0x002C5000 

- Run-time Dlls

 

Module Name

Base Address

Size

C:\WINDOWS\system32\Normaliz.dll 

0x00E80000 

0x00009000 

C:\WINDOWS\system32\iertutil.dll 

0x42990000 

0x00045000 

C:\WINDOWS\system32\WININET.dll 

0x42C10000 

0x000CF000 

17.a) spoolsv.exe - File Activities

 

- Device Control Communication:

 

File

Control Code

Times

unnamed file 

0x00228144