Analysis Summary:
| Analysis Date | 13.08.2006 00:34:11 |
|---|---|
| Sandbox Version | Beta 1.73 |
| Filename | 2bf2a4f0bdac42f4d6f8a062a7206797.exe |
Technical Details:
| Analysis Number | 1 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 0 | ||||||
| Process ID | 1820 | ||||||
| Filename | c:\analysis\binary\2bf2a4f0bdac42f4d6f8a062a7206797.exe | ||||||
| Filesize | 9374 bytes | ||||||
| MD5 | 2bf2a4f0bdac42f4d6f8a062a7206797 | ||||||
| Start Reason | AnalysisTarget | ||||||
| Termination Reason | NormalTermination | ||||||
| Start Time | 00:00.109 | ||||||
| Stop Time | 00:18.546 | ||||||
| Detection | OK
(ClamAV) Generic.Malware.IXdld.77C2258A (BDC/Linux-Console) OK (AntiVir Workstation) |
||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| Registry |
|
||||||
| Process Management |
Creates Process - Filename () CommandLine: (explorer.exe) As User: () Creation Flags: (CREATE_SUSPENDED) |
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "wgavm" Create Service - Name: (wgavm) Display Name: (Windows Genuine Advantage Validation Monitor) File Name: (C:\WINDOWS\system32\wgavm.exe) Control: () Start Type: (SERVICE_AUTO_START) Start Service - Name: (wgavm) Display Name: () File Name: () Control: () Start Type: () Change Service Configuration - Name: (wgavm) Display Name: () File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) Change Service Configuration - Name: (wgavm) Display Name: (Ensures that your copy of Microsoft Windows is genuine. Stopping or disabling this service will result in system instability.) File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) |
||||||
| System Info |
Get System Directory |
||||||
| Threads |
Create Remote Thread - Target PID (1632) Thread ID ($065C) Thread ID ($00090000) Parameter Address ($00000000) Creation Flags (CREATE_SUSPENDED) |
||||||
| Virtual Memory |
VM Allocate - Target: (1632) Address: ($00090000) Size: (4096) Protect: (PAGE_READWRITE) Allocation Type: (MEM_COMMIT) VM Allocate - Target: (1632) Address: ($000A0000) Size: (1048576) Protect: (PAGE_READWRITE) Allocation Type: (MEM_RESERVE) VM Allocate - Target: (1632) Address: ($0019E000) Size: (8192) Protect: (PAGE_READWRITE) Allocation Type: (MEM_COMMIT) VM Protect - Target: (1632) Address: ($00090000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1632) Address: ($00090000) Size: (4096) Protect: (PAGE_READWRITE) VM Protect - Target: (1632) Address: ($00090000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1632) Address: ($0019E000) Size: (4096) Protect: (PAGE_READWRITE,PAGE_GUARD) VM Write - Target: (1632) Address: ($00090000) Size: (52) VM Write - Target: (1632) Address: ($00090034) Size: (260) |
| Analysis Number | 2 |
|---|---|
| Parent ID | 0 |
| Process ID | 704 |
| Filename | services.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | SCM |
| Termination Reason | Timeout |
| Start Time | 00:16.125 |
| Stop Time | 02:01.234 |
| Process Management |
Creates Process - Filename () CommandLine: (C:\WINDOWS\system32\wgavm.exe) As User: () Creation Flags: (CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS) |
| Analysis Number | 3 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 2 | ||||||
| Process ID | 1260 | ||||||
| Filename | C:\WINDOWS\system32\wgavm.exe | ||||||
| Filesize | 9374 bytes | ||||||
| MD5 | 2bf2a4f0bdac42f4d6f8a062a7206797 | ||||||
| Start Reason | CreateProcess | ||||||
| Termination Reason | Timeout | ||||||
| Start Time | 00:16.734 | ||||||
| Stop Time | 02:01.250 | ||||||
| Detection | OK
(ClamAV) Generic.Malware.IXdld.77C2258A (BDC/Linux-Console) OK (AntiVir Workstation) |
||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| Mutexes |
Creates Mutex: wgavm |
||||||
| Registry |
|
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "sharedaccess" Control Service - Name: (sharedaccess) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Change Service Configuration - Name: (sharedaccess) Display Name: () File Name: () Control: () Start Type: (SERVICE_DISABLED) |
||||||
| System Info |
Get Windows Directory |
||||||
| Network Activity |
|
||||||
| Analysis Number | 4 |
|---|---|
| Parent ID | 1 |
| Process ID | 1632 |
| Filename | explorer.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | CreateProcess |
| Termination Reason | Timeout |
| Start Time | 00:18.062 |
| Stop Time | 02:01.093 |
Report generated at 13.08.2006 00:34:11 with CWSandbox Version Beta 1.73
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.