Analysis Summary:
| Analysis Date | 13.08.2006 00:34:48 |
|---|---|
| Sandbox Version | Beta 1.73 |
| Filename | 9928a1e6601cf00d0b7826d13fb556f0.exe |
Technical Details:
| Analysis Number | 1 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 0 | ||||||
| Process ID | 2004 | ||||||
| Filename | c:\analysis\binary\9928a1e6601cf00d0b7826d13fb556f0.exe | ||||||
| Filesize | 9609 bytes | ||||||
| MD5 | 9928a1e6601cf00d0b7826d13fb556f0 | ||||||
| Start Reason | AnalysisTarget | ||||||
| Termination Reason | NormalTermination | ||||||
| Start Time | 00:00.078 | ||||||
| Stop Time | 00:05.531 | ||||||
| Detection | OK
(ClamAV) Generic.Malware.IXdld.658BDD6B (BDC/Linux-Console) OK (AntiVir Workstation) |
||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| Registry |
|
||||||
| Process Management |
Creates Process - Filename () CommandLine: (explorer.exe) As User: () Creation Flags: (CREATE_SUSPENDED) |
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "wgareg" Create Service - Name: (wgareg) Display Name: (Windows Genuine Advantage Registration Service) File Name: (C:\WINDOWS\system32\wgareg.exe) Control: () Start Type: (SERVICE_AUTO_START) Start Service - Name: (wgareg) Display Name: () File Name: () Control: () Start Type: () Change Service Configuration - Name: (wgareg) Display Name: () File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) Change Service Configuration - Name: (wgareg) Display Name: (Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.) File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) |
||||||
| System Info |
Get System Directory |
||||||
| Threads |
Create Remote Thread - Target PID (600) Thread ID ($06FC) Thread ID ($00090000) Parameter Address ($00000000) Creation Flags (CREATE_SUSPENDED) |
||||||
| Virtual Memory |
VM Allocate - Target: (600) Address: ($00090000) Size: (4096) Protect: (PAGE_READWRITE) Allocation Type: (MEM_COMMIT) VM Allocate - Target: (600) Address: ($000A0000) Size: (1048576) Protect: (PAGE_READWRITE) Allocation Type: (MEM_RESERVE) VM Allocate - Target: (600) Address: ($0019E000) Size: (8192) Protect: (PAGE_READWRITE) Allocation Type: (MEM_COMMIT) VM Protect - Target: (600) Address: ($00090000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (600) Address: ($00090000) Size: (4096) Protect: (PAGE_READWRITE) VM Protect - Target: (600) Address: ($00090000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (600) Address: ($0019E000) Size: (4096) Protect: (PAGE_READWRITE,PAGE_GUARD) VM Write - Target: (600) Address: ($00090000) Size: (52) VM Write - Target: (600) Address: ($00090034) Size: (260) |
| Analysis Number | 2 |
|---|---|
| Parent ID | 0 |
| Process ID | 528 |
| Filename | services.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | SCM |
| Termination Reason | Timeout |
| Start Time | 00:01.438 |
| Stop Time | 02:01.156 |
| Process Management |
Creates Process - Filename () CommandLine: (C:\WINDOWS\system32\wgareg.exe) As User: () Creation Flags: (CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS) |
| Analysis Number | 3 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 2 | ||||||
| Process ID | 972 | ||||||
| Filename | C:\WINDOWS\system32\wgareg.exe | ||||||
| Filesize | 9609 bytes | ||||||
| MD5 | 9928a1e6601cf00d0b7826d13fb556f0 | ||||||
| Start Reason | CreateProcess | ||||||
| Termination Reason | Timeout | ||||||
| Start Time | 00:02.625 | ||||||
| Stop Time | 02:01.125 | ||||||
| Detection | OK
(ClamAV) Generic.Malware.IXdld.658BDD6B (BDC/Linux-Console) OK (AntiVir Workstation) |
||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| Mutexes |
Creates Mutex: wgareg |
||||||
| Registry |
|
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "sharedaccess" Control Service - Name: (sharedaccess) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Change Service Configuration - Name: (sharedaccess) Display Name: () File Name: () Control: () Start Type: (SERVICE_DISABLED) |
||||||
| System Info |
Get Windows Directory |
||||||
| Network Activity |
|
||||||
| Analysis Number | 4 |
|---|---|
| Parent ID | 1 |
| Process ID | 600 |
| Filename | explorer.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | CreateProcess |
| Termination Reason | Timeout |
| Start Time | 00:05.203 |
| Stop Time | 02:01.234 |
Report generated at 13.08.2006 00:34:48 with CWSandbox Version Beta 1.73
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.