<?xml version="1.0"?>
<!-- This analysis was created by the CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="Beta 1.73" time="13.08.2006 00:34:11" file="2bf2a4f0bdac42f4d6f8a062a7206797.exe" logpath="c:\analysis\log\2bf2a4f0bdac42f4d6f8a062a7206797.exe\run_1\">
<calltree>
<process_call filename="c:\analysis\binary\2bf2a4f0bdac42f4d6f8a062a7206797.exe" starttime="00:00.109" startreason="AnalysisTarget"><calltree>
<process_call filename="explorer.exe" starttime="00:18.062" startreason="CreateProcess"/>
</calltree>
</process_call>

<process_call filename="services.exe" starttime="00:16.125" startreason="SCM"><calltree>
<process_call filename="C:\WINDOWS\system32\wgavm.exe" starttime="00:16.734" startreason="CreateProcess"/>
</calltree>
</process_call>

</calltree>

<processes>
<process index="1" pid="1820" filename="c:\analysis\binary\2bf2a4f0bdac42f4d6f8a062a7206797.exe" filesize="9374" md5="2bf2a4f0bdac42f4d6f8a062a7206797" username="foobar" parentindex="0" starttime="00:00.109" terminationtime="00:18.546" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1650">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="444353">
<classification>Generic.Malware.IXdld.77C2258A</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.7-31" signature_file_version="6.35.1.84">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\analysis\binary\2bf2a4f0bdac42f4d6f8a062a7206797.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.dll" successful="1"/>
<load_dll dll="USER32.dll" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="ADVAPI32.dll" successful="1"/>
<load_dll dll="MSWSOCK.dll" successful="1"/>
<load_dll dll="VERSION.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\wgavm.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_ARCHIVE,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\analysis\binary\2bf2a4f0bdac42f4d6f8a062a7206797.exe" dstfile="C:\WINDOWS\system32\wgavm.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\explorer.exe" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="explorer.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<query_value key="\Registry\Machine\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<query_value key="\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers" subkey_or_value="C:\WINDOWS\explorer.exe"/>
<query_value key="\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags" subkey_or_value="&#x7B;8daa3198-f1f6-4d1d-9aa1-0a673bd3d3fb&#x7D;"/>
</registry_section>
<process_section>
<create_process commandline="explorer.exe" targetpid="1632" creationflags="CREATE_SUSPENDED" showwindow="SW_HIDE" apifunction="CreateProcessA" successful="1"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="wgavm"/>
<create_service servicename="wgavm" displayname="Windows Genuine Advantage Validation Monitor" filename="C:\WINDOWS\system32\wgavm.exe" starttype="SERVICE_AUTO_START"/>
<change_service_config servicename="wgavm" starttype="SERVICE_NO_CHANGE"/>
<change_service_config servicename="wgavm" displayname="Ensures that your copy of Microsoft Windows is genuine. Stopping or disabling this service will result in system instability." starttype="SERVICE_NO_CHANGE"/>
<start_service servicename="wgavm"/>
</service_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
<thread_section>
<create_thread_remote targetpid="1632" threadid="&#x24;065C" address="&#x24;00090000" parameteraddress="&#x24;00000000" creationflags="CREATE_SUSPENDED"/>
</thread_section>
<virtual_memory_section>
<vm_allocate targetpid="1632" wantedaddress="&#x24;00000000" address="&#x24;00090000" wantedsize="312" size="4096" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1632" address="&#x24;00090000" wantedsize="52" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_protect targetpid="1632" address="&#x24;00090000" wantedsize="4096" size="4096" protect="PAGE_READWRITE"/>
<vm_write targetpid="1632" address="&#x24;00090000" size="52"/>
<vm_protect targetpid="1632" address="&#x24;00090000" wantedsize="260" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1632" address="&#x24;00090034" size="260"/>
<vm_allocate targetpid="1632" wantedaddress="&#x24;00000000" address="&#x24;000A0000" wantedsize="1048576" size="1048576" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1632" wantedaddress="&#x24;0019E000" address="&#x24;0019E000" wantedsize="8192" size="8192" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1632" address="&#x24;0019E000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
</virtual_memory_section>
</process>
<process index="2" pid="704" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:16.125" terminationtime="02:01.234" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
<process_section>
<create_process commandline="C:\WINDOWS\system32\wgavm.exe" targetpid="1260" creationflags="CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS" showwindow="SW_HIDE" apifunction="CreateProcessW" successful="1"/>
</process_section>
</process>
<process index="3" pid="1260" filename="C:\WINDOWS\system32\wgavm.exe" filesize="9374" md5="2bf2a4f0bdac42f4d6f8a062a7206797" username="SYSTEM" parentindex="2" starttime="00:16.734" terminationtime="02:01.250" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1650">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="444353">
<classification>Generic.Malware.IXdld.77C2258A</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.7-31" signature_file_version="6.35.1.84">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\wgavm.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="KERNEL32.dll" successful="1"/>
<load_dll dll="USER32.dll" successful="1"/>
<load_dll dll="WS2_32.dll" successful="1"/>
<load_dll dll="ADVAPI32.dll" successful="1"/>
<load_dll dll="MSWSOCK.dll" successful="1"/>
<load_dll dll="dnsapi.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\debug\dcpromo.log" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="wgavm" owned="0"/>
</mutex_section>
<registry_section>
<create_open_key key="HKEY_LOCAL_MACHINE\software\microsoft\ole" subkey_or_value="software\microsoft\ole"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\ole" subkey_or_value="enabledcom" data="n"/>
<create_open_key key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="system\currentcontrolset\control\lsa"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="restrictanonymous" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" subkey_or_value="restrictanonymoussam" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="system\currentcontrolset\services\lanmanserver\parameters"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="autoshareserver" data="[REG_DWORD, value: 00000000]"/>
<set_value key="HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lanmanserver\parameters" subkey_or_value="autosharewks" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="software\microsoft\security center"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="antivirusdisablenotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="antivirusoverride" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="firewalldisablenotify" data="[REG_DWORD, value: 00000001]"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\security center" subkey_or_value="firewalldisableoverride" data="[REG_DWORD, value: 00000001]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\domainprofile" subkey_or_value="software\policies\microsoft\windowsfirewall\domainprofile"/>
<set_value key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\domainprofile" subkey_or_value="enablefirewall" data="[REG_DWORD, value: 00000000]"/>
<create_open_key key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\standardprofile" subkey_or_value="software\policies\microsoft\windowsfirewall\standardprofile"/>
<set_value key="HKEY_LOCAL_MACHINE\software\policies\microsoft\windowsfirewall\standardprofile" subkey_or_value="enablefirewall" data="[REG_DWORD, value: 00000000]"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
</registry_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="sharedaccess"/>
<control_service servicename="sharedaccess" control="SERVICE_CONTROL_STOP"/>
<change_service_config servicename="sharedaccess" starttype="SERVICE_DISABLED"/>
</service_section>
<system_info_section>
<get_windows_directory/>
</system_info_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="bniu.househot.com" resulting_addr="61.163.231.115"/>
</connection>
</connections_unknown>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="61.163.231.115" remoteport="18067" connectionestablished="0" socket="1220">
<plain_communication_data>
<send>USeR l l l l.</send>
<send>NiCK n0-01679410.</send>
</plain_communication_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
<process index="4" pid="1632" filename="explorer.exe" filesize="-1" username="foobar" parentindex="1" starttime="00:18.062" terminationtime="02:01.093" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
</process>
</processes>
</analysis>
