<?xml version="1.0"?>
<!-- This analysis was created by the CWSandbox (c) Carsten Willems 2006-->
<analysis cwsversion="Beta 1.83" time="23.11.2006 13:12:12" file="508ffdec653b5e75cdd7d7312d9648c1.exe" logpath="c:\analysis\log\508ffdec653b5e75cdd7d7312d9648c1.exe\run_1\">
<calltree>
<process_call filename="c:\508ffdec653b5e75cdd7d7312d9648c1.exe" starttime="00:00.047" startreason="AnalysisTarget"><calltree>
<process_call filename="c:\loaders.exe c:\loaders.exe" starttime="00:13.953" startreason="CreateProcess"/>
</calltree>
</process_call>

<process_call filename="services.exe" starttime="00:05.828" startreason="SCM"><calltree>
<process_call filename="C:\WINDOWS\system32\lxsys.exe" starttime="00:20.734" startreason="CreateProcess"/>
</calltree>
</process_call>

</calltree>

<processes>
<process index="1" pid="1540" filename="c:\508ffdec653b5e75cdd7d7312d9648c1.exe" filesize="21879" md5="508ffdec653b5e75cdd7d7312d9648c1" username="foobar" parentindex="0" starttime="00:00.047" terminationtime="02:00.187" startreason="AnalysisTarget" terminationreason="Timeout" executionstatus="OK">
<com_section>
<com_get_class_object inprocserver32="C:\WINDOWS\system32\urlmon.dll" interfaceid="{00000001-0000-0000-C000-000000000046}"/>
</com_section>
<dll_handling_section>
<load_dll dll="c:\508ffdec653b5e75cdd7d7312d9648c1.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSVBVM60.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\VB6DE.DLL" successful="0"/>
<load_dll dll="uxtheme.dll" successful="1"/>
<load_dll dll="OLEAUT32.DLL" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="urlmon" successful="1"/>
<load_dll dll="mlang.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="kernel32.dll" successful="1"/>
<load_dll dll="WININET.dll" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="SHELL32.dll" successful="1"/>
<load_dll dll="USERENV.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="netapi32" successful="1"/>
<load_dll dll="ole32.dll" successful="1"/>
<load_dll dll="VERSION.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\foobar\Application Data\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Documents and Settings\foobar\Local Settings\Temporary Internet Files\Content.IE5\A360B5YU\loader[1].exe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="c:\loaders.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\wkssvc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\loaders.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\Documents and Settings\foobar\My Documents\desktop.ini" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\Documents and Settings\All Users\Documents\desktop.ini" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\Registration" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\Registration\R000000000014.clb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\loaders.exe:Zone.Identifier" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\loaders.exe" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="loaders.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<ini_file_section>
<read_value file="C:\Documents and Settings\foobar\My Documents\desktop.ini" section="DeleteOnCopy" value="Owner"/>
<read_value file="C:\Documents and Settings\foobar\My Documents\desktop.ini" section="DeleteOnCopy.A" value="Owner"/>
<read_value file="C:\Documents and Settings\foobar\My Documents\desktop.ini" section="DeleteOnCopy" value="PersonalizedName"/>
<read_value file="C:\Documents and Settings\foobar\My Documents\desktop.ini" section="DeleteOnCopy.A" value="PersonalizedName"/>
<read_value file="C:\Documents and Settings\All Users\Documents\desktop.ini" section="DeleteOnCopy" value="Owner"/>
<read_value file="C:\Documents and Settings\All Users\Documents\desktop.ini" section=".ShellClassInfo" value="LocalizedResourceName"/>
</ini_file_section>
<mutex_section>
<create_mutex name="ZonesCounterMutex" owned="0"/>
<create_mutex name="ZonesCacheCounterMutex" owned="0"/>
<create_mutex name="ZonesLockedCacheCounterMutex" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
</mutex_section>
<registry_section>
<query_value key="Software\Microsoft\Windows\CurrentVersion\ThemeManager" subkey_or_value="Compositing"/>
<query_value key="Control Panel\Desktop" subkey_or_value="LameButtonText"/>
<enum_keys key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="DisableImprovedZoneCheck"/>
<create_open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager" subkey_or_value="Software\Microsoft\DownloadManager"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager" subkey_or_value="CacheOk"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="User Agent"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Pre Platform"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
<query_value key="HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="IsTextPlainHonored"/>
<query_value key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\\Registry\Machine\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<query_value key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers" subkey_or_value="c:\loaders.exe"/>
</registry_section>
<process_section>
<create_process filename="c:\loaders.exe" showwindow="SW_SHOWNORMAL" apifunction="ShellExecuteA" successful="1"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_computer_name/>
<get_system_directory/>
</system_info_section>
<user_section>
<impersonate_user user="foobar" tokenhandle="1504"/>
<get_username tokenhandle="0"/>
</user_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
</connection>
</connections_unknown>
<connections_udp>
<connection transportprotocol="UDP" connectionestablished="0" socket="1468">
</connection>
<connection transportprotocol="UDP" connectionestablished="0" socket="-1">
</connection>
</connections_udp>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="68.142.212.124" remoteport="80" protocol="HTTP" connectionestablished="1" socket="1532">
<http_data>
<http_cmd method="GET" url="/loader.exe" http_version="HTTP/1.1"/>
</http_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
<process index="2" pid="704" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:05.828" terminationtime="02:00.422" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
<process_section>
<create_process commandline="&quot;C:\WINDOWS\system32\lxsys.exe&quot;" targetpid="1484" creationflags="CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS" showwindow="SW_HIDE" apifunction="CreateProcessW" successful="1"/>
</process_section>
</process>
<process index="3" pid="1416" filename="c:\loaders.exe c:\loaders.exe" filesize="-1" username="foobar" parentindex="1" starttime="00:13.953" terminationtime="00:25.812" startreason="CreateProcess" terminationreason="NormalTermination" executionstatus="OK">
<dll_handling_section>
<load_dll dll="c:\loaders.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.DLL" successful="1"/>
<load_dll dll="MSVCRT.dll" successful="1"/>
<load_dll dll="user32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="icmp.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="dnsapi.dll" successful="1"/>
<load_dll dll="iphlpapi.dll" successful="1"/>
<load_dll dll="mpr.dll" successful="1"/>
<load_dll dll="shell32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\odbcint.dll" successful="1"/>
<load_dll dll="odbc32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_open_file filetype="File" srcfile="\Device\Tcp" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\\.\Ip" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\lxsys.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\loaders.exe" dstfile="C:\WINDOWS\system32\lxsys.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWSExplorer.exe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\lxsys.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_HIDDEN,FILE_ATTRIBUTE_READONLY,FILE_ATTRIBUTE_SYSTEM,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" subkey_or_value="Shell"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions" subkey_or_value="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions" subkey_or_value="jda30" data="c:\loaders.exe"/>
</registry_section>
<process_section>
<kill_process targetpid="1416" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<create_service servicename="Window LFX Services" displayname="Window LFX Services" filename="&quot;C:\WINDOWS\system32\lxsys.exe&quot;" starttype="SERVICE_AUTO_START" servicetype="SERVICE_WIN32_OWN_PROCESS,SERVICE_INTERACTIVE_PROCESS" desiredaccess="SERVICE_ALL_ACCESS"/>
<open_service servicename="Window LFX Services" desiredaccess="SERVICE_ALL_ACCESS"/>
<change_service_config servicename="Window LFX Services" starttype="SERVICE_NO_CHANGE"/>
<change_service_config servicename="Window LFX Services" displayname="Window LFX Services" starttype="SERVICE_NO_CHANGE"/>
<start_service servicename="Window LFX Services"/>
</service_section>
<system_info_section>
<get_windows_directory/>
</system_info_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
</connection>
</connections_unknown>
</winsock_section>

</process>
<process index="4" pid="1484" filename="C:\WINDOWS\system32\lxsys.exe" filesize="46372" md5="ad09bf5997fc4a30012eb73e553c6830" username="SYSTEM" parentindex="2" starttime="00:20.734" terminationtime="02:00.250" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\lxsys.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.DLL" successful="1"/>
<load_dll dll="MSVCRT.dll" successful="1"/>
<load_dll dll="user32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="icmp.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="dnsapi.dll" successful="1"/>
<load_dll dll="iphlpapi.dll" successful="1"/>
<load_dll dll="mpr.dll" successful="1"/>
<load_dll dll="shell32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\odbcint.dll" successful="1"/>
<load_dll dll="odbc32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_open_file filetype="File" srcfile="\Device\Tcp" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\\.\Ip" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<set_file_attributes filetype="File" srcfile="c:\loaders.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\loaders.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="c:\loaders.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\srvsvc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="NCI_CHAR(0x08)_" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
</mutex_section>
<network_section>
<enum_share/>
<delete_share networkressource="IPC$"/>
<delete_share networkressource="ADMIN$"/>
<delete_share networkressource="C$"/>
</network_section>
<registry_section>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions" subkey_or_value="jda30"/>
<delete_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions" subkey_or_value="jda30"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" subkey_or_value="SYSTEM\CurrentControlSet\Control"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" subkey_or_value="WaitToKillServiceTimeout" data="7000"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="TaskMon"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="PandaAVEngine"/>
<query_value key="HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="sysinfo.exe"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="System MScvb"/>
<query_value key="HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="System MScvb"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="windows auto update"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="Microsoft Inet Xp.."/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="d3dupdate.exe"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="ssate.exe"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="rate.exe"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="SOFTWARE\Microsoft\Security Center"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="UpdatesDisableNotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="AntiVirusDisableNotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="FirewallDisableNotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="AntiVirusOverride" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" subkey_or_value="FirewallOverride" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile" subkey_or_value="SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile" subkey_or_value="EnableFirewall" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile" subkey_or_value="SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile" subkey_or_value="EnableFirewall" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" subkey_or_value="SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" subkey_or_value="AUOptions" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc" subkey_or_value="SYSTEM\CurrentControlSet\Services\wscsvc"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc" subkey_or_value="Start" data="[REG_DWORD, value: 00000004]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr" subkey_or_value="SYSTEM\CurrentControlSet\Services\TlntSvr"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr" subkey_or_value="Start" data="[REG_DWORD, value: 00000004]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry" subkey_or_value="SYSTEM\CurrentControlSet\Services\RemoteRegistry"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry" subkey_or_value="Start" data="[REG_DWORD, value: 00000004]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger" subkey_or_value="SYSTEM\CurrentControlSet\Services\Messenger"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger" subkey_or_value="Start" data="[REG_DWORD, value: 00000004]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa" subkey_or_value="SYSTEM\CurrentControlSet\Control\Lsa"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa" subkey_or_value="restrictanonymous" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters" subkey_or_value="SYSTEM\CurrentControlSet\Services\lanmanserver\parameters"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters" subkey_or_value="AutoShareWks" data="[REG_DWORD, value: 00000000]"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters" subkey_or_value="AutoShareServer" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters" subkey_or_value="SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters" subkey_or_value="AutoShareWks" data="[REG_DWORD, value: 00000000]"/>
<set_value key="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters" subkey_or_value="AutoShareServer" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" subkey_or_value="SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate"/>
<set_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" subkey_or_value="DoNotAllowXPSP2" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\OLE" subkey_or_value="Software\Microsoft\OLE"/>
<set_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\OLE" subkey_or_value="EnableDCOM" data="N"/>
</registry_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="Tlntsvr" desiredaccess="SERVICE_ALL_ACCESS"/>
<control_service servicename="Tlntsvr" control="SERVICE_CONTROL_STOP"/>
<open_service servicename="RemoteRegistry" desiredaccess="SERVICE_ALL_ACCESS"/>
<control_service servicename="RemoteRegistry" control="SERVICE_CONTROL_STOP"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
<open_service servicename="Messenger" desiredaccess="SERVICE_ALL_ACCESS"/>
<control_service servicename="Messenger" control="SERVICE_CONTROL_STOP"/>
<open_service servicename="SharedAccess" desiredaccess="SERVICE_ALL_ACCESS"/>
<control_service servicename="SharedAccess" control="SERVICE_CONTROL_STOP"/>
<open_service servicename="wscsvc" desiredaccess="SERVICE_ALL_ACCESS"/>
<control_service servicename="wscsvc" control="SERVICE_CONTROL_STOP"/>
</service_section>
<system_info_section>
<get_computer_name/>
</system_info_section>
<window_section>
<find_window classname="mIRC"/>
<find_window classname="AIM_CSignOnWnd"/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="hi.ircstyle.net" resulting_addr="85.17.40.94"/>
<gethostbyname requested_host="example.org" resulting_addr="123.456.789.abc"/>
</connection>
</connections_unknown>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="IRC" connectionestablished="1" socket="1584">
<irc_data username="XP-2940 * 0 :FOO" password="nadjoe" nick="[00|DEU|459044]">
<channel name="##d.r"/>
<notice_deleted value=":hub.415.com NOTICE [00|DEU|459044] :*** You are permanently banned from hub.415.com (no reason)"/>
</irc_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1616">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|465443]..</send>
<send>USER XP-2099 * 0 :FOO..</send>
<recv>:hub.415.com NOTICE [00|DEU|465443] :*** You are permanently banned from hub.415.com (no reason)..ERROR :Closing Link: [00|DEU|465443][example.org] (User is permanently banned (no reason))..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1608">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|358164]..</send>
<send>USER XP-1358 * 0 :FOO..</send>
<recv>:hub.415.com NOTICE [00|DEU|358164] :*** You are permanently banned from hub.415.com (no reason)..ERROR :Closing Link: [00|DEU|358164][example.org] (User is permanently banned (no reason))..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1632">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|176772]..</send>
<send>USER XP-2638 * 0 :FOO..</send>
<recv>ERROR :Closing Link: [123.456.789.abc] (Throttled: Reconnecting too fast) -Email DIE@DIE.COM for more information.)..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1644">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|962677]..</send>
<send>USER XP-7217 * 0 :FOO..</send>
<recv>ERROR :Closing Link: [123.456.789.abc] (Throttled: Reconnecting too fast) -Email DIE@DIE.COM for more information.)..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1656">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|228689]..</send>
<send>USER XP-9543 * 0 :FOO..</send>
<recv>ERROR :Closing Link: [123.456.789.abc] (Throttled: Reconnecting too fast) -Email DIE@DIE.COM for more information.)..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1668">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|590542]..</send>
<send>USER XP-4908 * 0 :FOO..</send>
<recv>ERROR :Closing Link: [123.456.789.abc] (Throttled: Reconnecting too fast) -Email DIE@DIE.COM for more information.)..</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1680">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|288586]..</send>
<send>USER XP-6703 * 0 :FOO..</send>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="85.17.40.94" remoteport="8080" protocol="Unknown" connectionestablished="1" socket="1692">
<plain_communication_data>
<send>PASS nadjoe..</send>
<send>NICK [00|DEU|108154]..</send>
<send>USER XP-3189 * 0 :FOO..</send>
</plain_communication_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
</processes>
</analysis>
