<?xml version="1.0"?>
<!-- This analysis was created by the CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="Beta 1.73" time="13.08.2006 00:34:48" file="9928a1e6601cf00d0b7826d13fb556f0.exe" logpath="c:\analysis\log\9928a1e6601cf00d0b7826d13fb556f0.exe\run_1\">
<calltree>
<process_call filename="c:\analysis\binary\9928a1e6601cf00d0b7826d13fb556f0.exe" starttime="00:00.078" startreason="AnalysisTarget"><calltree>
<process_call filename="explorer.exe" starttime="00:05.203" startreason="CreateProcess"/>
</calltree>
</process_call>

<process_call filename="services.exe" starttime="00:01.438" startreason="SCM"><calltree>
<process_call filename="C:\WINDOWS\system32\wgareg.exe" starttime="00:02.625" startreason="CreateProcess"/>
</calltree>
</process_call>

</calltree>

<processes>
<process index="1" pid="2004" filename="c:\analysis\binary\9928a1e6601cf00d0b7826d13fb556f0.exe" filesize="9609" md5="9928a1e6601cf00d0b7826d13fb556f0" username="foobar" parentindex="0" starttime="00:00.078" terminationtime="00:05.531" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1650">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="444353">
<classification>Generic.Malware.IXdld.658BDD6B</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.7-31" signature_file_version="6.35.1.84">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\analysis\binary\9928a1e6601cf00d0b7826d13fb556f0.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.dll" successful="1"/>
<load_dll dll="USER32.dll" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="ADVAPI32.dll" successful="1"/>
<load_dll dll="MSWSOCK.dll" successful="1"/>
<load_dll dll="VERSION.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\wgareg.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_ARCHIVE,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\analysis\binary\9928a1e6601cf00d0b7826d13fb556f0.exe" dstfile="C:\WINDOWS\system32\wgareg.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\explorer.exe" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="explorer.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<query_value key="\Registry\Machine\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<query_value key="\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers" subkey_or_value="C:\WINDOWS\explorer.exe"/>
<query_value key="\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags" subkey_or_value="&#x7B;8daa3198-f1f6-4d1d-9aa1-0a673bd3d3fb&#x7D;"/>
</registry_section>
<process_section>
<create_process commandline="explorer.exe" targetpid="600" creationflags="CREATE_SUSPENDED" showwindow="SW_HIDE" apifunction="CreateProcessA" successful="1"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="wgareg"/>
<create_service servicename="wgareg" displayname="Windows Genuine Advantage Registration Service" filename="C:\WINDOWS\system32\wgareg.exe" starttype="SERVICE_AUTO_START"/>
<change_service_config servicename="wgareg" starttype="SERVICE_NO_CHANGE"/>
<change_service_config servicename="wgareg" displayname="Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability." starttype="SERVICE_NO_CHANGE"/>
<start_service servicename="wgareg"/>
</service_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
<thread_section>
<create_thread_remote targetpid="600" threadid="&#x24;06FC" address="&#x24;00090000" parameteraddress="&#x24;00000000" creationflags="CREATE_SUSPENDED"/>
</thread_section>
<virtual_memory_section>
<vm_allocate targetpid="600" wantedaddress="&#x24;00000000" address="&#x24;00090000" wantedsize="312" size="4096" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="600" address="&#x24;00090000" wantedsize="52" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_protect targetpid="600" address="&#x24;00090000" wantedsize="4096" size="4096" protect="PAGE_READWRITE"/>
<vm_write targetpid="600" address="&#x24;00090000" size="52"/>
<vm_protect targetpid="600" address="&#x24;00090000" wantedsize="260" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="600" address="&#x24;00090034" size="260"/>
<vm_allocate targetpid="600" wantedaddress="&#x24;00000000" address="&#x24;000A0000" wantedsize="1048576" size="1048576" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="600" wantedaddress="&#x24;0019E000" address="&#x24;0019E000" wantedsize="8192" size="8192" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="600" address="&#x24;0019E000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
</virtual_memory_section>
</process>
<process index="2" pid="528" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:01.438" terminationtime="02:01.156" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
<process_section>
<create_process commandline="C:\WINDOWS\system32\wgareg.exe" targetpid="972" creationflags="CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS" showwindow="SW_HIDE" apifunction="CreateProcessW" successful="1"/>
</process_section>
</process>
<process index="3" pid="972" filename="C:\WINDOWS\system32\wgareg.exe" filesize="9609" md5="9928a1e6601cf00d0b7826d13fb556f0" username="SYSTEM" parentindex="2" starttime="00:02.625" terminationtime="02:01.125" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1650">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="444353">
<classification>Generic.Malware.IXdld.658BDD6B</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.7-31" signature_file_version="6.35.1.84">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\wgareg.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.dll" successful="1"/>
<load_dll dll="USER32.dll" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="ADVAPI32.dll" successful="1"/>
<load_dll dll="MSWSOCK.dll" successful="1"/>
<load_dll dll="dnsapi.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\debug\dcpromo.log" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="wgareg" owned="0"/>
</mutex_section>
<registry_section>
<create_open_key key="HKEY_LOCAL_MACHINE\software\microsoft\ole" subkey_or_value="software\microsoft\ole"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\ole" subkey_or_value="enabledcom" data="n"/>
<create_open_key key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="system\currentcontrolset\control\lsa"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="restrictanonymous" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="restrictanonymoussam" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="system\currentcontrolset\services\lanmanserver\parameters"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="autoshareserver" data="[REG_DWORD, value: 00000000]"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="autosharewks" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="software\microsoft\security center"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="antivirusdisablenotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="antivirusoverride" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="firewalldisablenotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="firewalldisableoverride" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\domainprofile" subkey_or_value="software\policies\microsoft\windowsfirewall\domainprofile"/>
<set_value key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\domainprofile" subkey_or_value="enablefirewall" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\standardprofile" subkey_or_value="software\policies\microsoft\windowsfirewall\standardprofile"/>
<set_value key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\standardprofile" subkey_or_value="enablefirewall" data="[REG_DWORD, value: 00000000]"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
</registry_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="sharedaccess"/>
<control_service servicename="sharedaccess" control="SERVICE_CONTROL_STOP"/>
<change_service_config servicename="sharedaccess" starttype="SERVICE_DISABLED"/>
</service_section>
<system_info_section>
<get_windows_directory/>
</system_info_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="bniu.househot.com" resulting_addr="61.189.243.240"/>
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1424">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1432">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1436">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1440">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1444">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1448">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1452">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1456">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1460">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1464">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1468">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1472">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1476">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1480">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1484">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1488">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1492">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1496">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1500">
</connection>
<connection transportprotocol="TCP" connectionestablished="0" socket="1504">
</connection>
</connections_unknown>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="61.189.243.240" remoteport="18067" protocol="IRC" connectionestablished="1" socket="1220">
<username value="n1-00b81cd0"/>
<password/>
<nick value="n1-00b81cd0"/>
<action>Joined channel &#x23;n1 nert4mp1</action>
</connection>
</connections_outgoing>
<connections_outgoing_blocked>
<connection transportprotocol="TCP" remoteaddr="134.184.35.0" remoteport="445" connectionestablished="0" socket="1256">
</connection>
<connection transportprotocol="TCP" remoteaddr="134.155.35.0" remoteport="445" connectionestablished="0" socket="1252">
</connection>
<connection transportprotocol="TCP" remoteaddr="134.155.35.1" remoteport="445" connectionestablished="0" socket="1260">
</connection>
<connection transportprotocol="TCP" remoteaddr="134.184.35.1" remoteport="445" connectionestablished="0" socket="1264">
</connection>
<connection transportprotocol="TCP" remoteaddr="134.155.35.2" remoteport="445" connectionestablished="0" socket="1268">
</connection>
</connections_outgoing_blocked>
</winsock_section>

</process>
<process index="4" pid="600" filename="explorer.exe" filesize="-1" username="foobar" parentindex="1" starttime="00:05.203" terminationtime="02:01.234" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
</process>
</processes>
</analysis>
