Joebox - Abstract Analysis File 5779
General information
Joebox version: 4.2.5
Start time: 13:56:29
Start date: 16/09/2011
Overall analysis duration: 0h 3m 10s
Target binary file name: bb5511a6586ba04335712e6c65e83671
Target script file name: default.jbs
Number of analysed new started processes analysed: 1
Number of new started drivers analysed: 1
Number of existing processes analysed: 0
Number of existing drivers analysed: 0
Number of injected processes analysed: 0
Errors:
    Summary
    • Binary contains device paths (device paths are often used for kernelmode <-> usermode communication)
    • Binary contains paths to debug symbols
    • Creates temporary files
    • Printf formatting strings found in memory and binary data
    • Queries a list of all running processes
    • Creates files inside the driver directory
    • Creates files inside the system directory
    • Creates driver files
    • Binary may include packed or crypted data
    • Infectes the boot sector of the hard disk
    • Modifies IRP (I/O request packets) handlers (IRP hooks)
    • Spawns drivers
    Static File Information
    PE Information
    General
    Entrypoint: 0x4025d0L .text
    Imagebase: 0x400000L
    Time stamp: 0x4CB57A1C [Wed Oct 13 09:21:32 2010 UTC]
    Subsystem: windows gui
    TLS callbacks:
    Resources
    Name RVA address Size Type
    Chinese 0x5194L 0x16f27L data
    Chinese 0x1c0bcL 0xc37L data
    Chinese 0x1ccf4L 0x52fL 8086 relocatable (Microsoft)
    Chinese 0x1d224L 0x3d68L data
    Chinese 0x20f8cL 0x8d7L data
    Chinese 0x21864L 0x7aL data
    Imports
    DLL Import
    MSVCRT ??1type_info@@UAE@XZ, _CxxThrowException, strcpy, strrchr, printf, __CxxFrameHandler, _access, strcat, sprintf, strlen, ??2@YAPAXI@Z, memset, memcpy, ??3@YAXPAX@Z, _strcmpi
    PSAPI.DLL GetProcessMemoryInfo
    KERNEL32.dll lstrcmpiA, Process32Next, CreateToolhelp32Snapshot, Process32First, OutputDebugStringA, GetLastError, CreateFileA, CloseHandle, GetCurrentProcess, ReadFile, SetFilePointer, WriteFile, GetFileSize, CreateProcessA, GetModuleFileNameA, GetModuleHandleA, GetTempPathA, MoveFileExA, CopyFileA, DeleteFileA, LockResource, SizeofResource, LoadResource, FindResourceA, GetVersionExA, WaitForSingleObject, GetStartupInfoA, Sleep, DeviceIoControl, GetWindowsDirectoryA, LoadLibraryA, GetCommandLineA, GetProcAddress, VirtualProtect, VirtualQuery, GetSystemDirectoryA
    USER32.dll PostQuitMessage, SetWindowLongA, SetTimer, KillTimer, DialogBoxParamA, GetWindowLongA, EndDialog
    ADVAPI32.dll AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, CloseServiceHandle, DeleteService, ControlService, OpenServiceA, OpenSCManagerA, QueryServiceStatus, StartServiceA
    Exports
    Sections
    Name Virtual address Virtual size Raw size entropy
    .text 0x1000L 0x1ebaL 0x2000L 6.4537205467
    .rdata 0x3000L 0x88aL 0xa00L 4.44922049448
    .data 0x4000L 0x340L 0x400L 3.11987816544
    .rsrc 0x5000L 0x1c8e0L 0x1ca00L 7.99679710705
    Version Infos
    Description Data
    Possible Origin
    Language of compilation system Country where language is spoken Map
    Chinese China
    String Analysis
    Debug symbol paths
    String value Source
    D:\VC++\Projects\MBR\MBR\mbr\hide_sector\hide_sector1\i386\hide_sector.pdb ~DFE0F5.tmp.dr
    d:\vc++\projects\mbr\bios\bios_operate\i386\bios.pdb ~DFE0F5.tmp.dr
    Formattings for printf style functions
    String value Source
    SMI_PORT = 0x%x. ~DFE0F5.tmp.dr
    Open the bios file failed! 0x%x ~DFE0F5.tmp.dr
    }DF7C%g bb5511a6586ba04335712e6c65e83671.exe
    Assertion failed: %s, file %s, line %d bb5511a6586ba04335712e6c65e83671.exe
    %s %s /isa release bb5511a6586ba04335712e6c65e83671.exe
    %s %s /isa %s bb5511a6586ba04335712e6c65e83671.exe
    PvtS%D bb5511a6586ba04335712e6c65e83671.exe
    BIOSSize(KB) = 0x%x. ~DFE0F5.tmp.dr
    Read the bios file failed! 0x%x ~DFE0F5.tmp.dr
    MmMapIoSpace physics address:0x%x failed. ~DFE0F5.tmp.dr
    [-]OpenSCManager Failed in LoadDriver %d bb5511a6586ba04335712e6c65e83671.exe
    Analysis Overview
    Startup
    • system is xp
    • bb5511a6586ba04335712e6c65e83671.exe (PID: 992 MD5: BB5511A6586BA04335712E6C65E83671)
    • Beep.SYS (PID: 4 MD5: CDDE77A83EA545C14B22C32CA9655BDD)
    • cleanup
    Dropped Files
    File Path MD5
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp EEFC6AC988588F64EE5C1B39DEBC9F91
    \Device\Harddisk0\DR0 32ECCFF16F18F4FE1B3C1A96E3A0A708
    c:\my.sys (copy) EEFC6AC988588F64EE5C1B39DEBC9F91
    Global Network Data
    Hooks
    IRP Handler
    Handler Function Driver Address Type
    IRP_MJ_DEVICE_CONTROL \Driver\Beep FB07E400 modified
    IRP_MJ_CLEANUP \Driver\Beep FB07E354 modified
    IRP_MJ_CLOSE \Driver\Beep FB07E4B8 modified
    IRP_MJ_CREATE \Driver\Beep FB07E46A modified
    New Devices
    Driver Device Attached to (lower) Attached to (upper)
    \Driver\Beep \Device\Bios
    Device Extensions
    Driver Device Extension Before Extension After
    Analysis File: bb5511a6586ba04335712e6c65e83671.exe PID: 992 Parent PID: 936
    Sections
    General
    Start time: 04:47:00
    Start date: 16/09/2011
    Path: C:\bb5511a6586ba04335712e6c65e83671.exe
    Commandline: not known
    Imagebase: 0x400000
    File size: 130048 bytes
    MD5 hash: BB5511A6586BA04335712E6C65E83671
    File Activities:
    File opened
    File Path Access Options Content overwritten Completion Count Source Address
    MyDeviceDriver read attributes and synchronize and generic read and generic write synchronous io non alert and non directory file false 12FAD0 1 401D62
    Bios read attributes and synchronize and generic read and generic write synchronous io non alert and non directory file true success or wait 1 40202F
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom read attributes and synchronize and generic read and generic write synchronous io non alert and non directory file false success or wait 1 401194
    PHYSICALDRIVE0 read attributes and synchronize and generic read and generic write synchronous io non alert and non directory file false success or wait 1 4010B5
    File created
    File Path Access Attributes Options Completion Count Source Address
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize none synchronous io non alert and non directory file success or wait 3 4013EA
    File deleted
    File Path Completion Count Source Address
    C:\WINDOWS\system32\drivers\beep.sys success or wait 1 40181A
    C:\WINDOWS\system32\drivers\bios.sys success or wait 1 402013
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp success or wait 1 4014ED
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom success or wait 1 4021FF
    File renamed
    Old File Path New File Path Completion Count Source Address
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp C:\WINDOWS\system32\drivers\bios.sys success or wait 2 401508
    C:\WINDOWS\system32\drivers\beep.sys C:\WINDOWS\system32\drivers\beep.sys.bak success or wait 1 4017F6
    C:\WINDOWS\system32\drivers\bios.sys1 C:\WINDOWS\system32\drivers\beep.sys success or wait 1 401993
    C:\WINDOWS\system32\drivers\bios.sys2 C:\WINDOWS\system32\dllcache\beep.sysba success or wait 1 4019A9
    C:\WINDOWS\system32\drivers\beep.sys.bak C:\WINDOWS\system32\drivers\beep.sys success or wait 1 401832
    File copied
    Old File Path New File Path Completion Count Source Address
    C:\WINDOWS\system32\drivers\bios.sys C:\WINDOWS\system32\drivers\bios.sys1 success or wait 1 401941
    C:\WINDOWS\system32\drivers\bios.sys C:\WINDOWS\system32\drivers\bios.sys2 success or wait 1 401981
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp c:\my.sys success or wait 1 4014DC
    File written
    File Path Offset Length Value Completion Count Source Address
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp none 5632 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 success or wait 1 4014A2
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp none 2688 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 C8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 success or wait 1 4014A2
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp none 7680 55 AA 0F E9 4E 00 00 00 00 00 00 00 00 6A 00 00 00 00 00 00 00 00 00 00 1C 00 34 00 50 43 49 52 EC 10 39 81 00 00 18 00 00 02 00 00 08 00 01 02 00 80 00 00 24 50 6E 50 01 02 00 00 00 65 00 00 00 00 00 00 00 00 02 00 00 64 00 00 00 00 00 00 00 00 00 00 9C 66 60 06 1E FC E8 00 1C 33 C0 8E D0 BC 00 7C success or wait 1 4014A2
    \Device\Harddisk0\DR0 none 7168 33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC 50 BE 00 7C BF 00 06 B9 00 02 F3 A4 BF 1E 06 57 CB B4 41 B2 80 BB AA 55 CD 13 81 FB 55 AA 75 30 F6 C1 01 74 2B BE 00 08 C7 04 10 00 C7 44 02 06 00 C7 44 04 00 7C C7 44 06 00 00 C6 44 08 01 B9 07 00 BF 09 08 C6 05 00 47 E2 FA B8 00 42 EB 0B B8 06 02 BB 00 7C B9 success or wait 1 401150
    File read
    File Path Offset Length Value Completion Count Source Address
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom none 7680 55 AA 0F E9 4E 00 00 00 00 00 00 00 00 6A 00 00 00 00 00 00 00 00 00 00 1C 00 34 00 50 43 49 52 EC 10 39 81 00 00 18 00 00 02 00 00 08 00 01 02 00 80 00 00 24 50 6E 50 01 02 00 00 00 65 00 00 00 00 00 00 00 00 02 00 00 64 00 00 00 00 00 00 00 00 00 00 9C 66 60 06 1E FC E8 00 1C 33 C0 8E D0 BC 00 7C success or wait 1 4011D4
    \Device\Harddisk0\DR0 none 512 33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C success or wait 1 401106
    Other file operations
    File Path Disposition Data Ascii Data Completion Count Source Address
    \Device\Harddisk0\DR0 PositionInformation Offset: 0 success or wait 2 4010EB
    Section Activities:
    Section loaded by Windows
    File Path Access Type Base Size Mapped to pid Protection Completion Count
    \KnownDlls\kernel32.dll write and read and execute image 7C800000 1007616 own pid read write success or wait 1
    \NLS\NlsSectionUnicode read image 260000 90112 own pid readonly success or wait 1
    \NLS\NlsSectionLocale read image 280000 266240 own pid readonly success or wait 1
    \NLS\NlsSectionSortkey query and read image 2D0000 266240 own pid readonly success or wait 1
    \NLS\NlsSectionSortTbls read image 320000 24576 own pid readonly success or wait 1
    \KnownDlls\MSVCRT.dll write and read and execute image 77C10000 360448 own pid read write success or wait 1
    C:\WINDOWS\system32\psapi.dll query and write and read and execute image 76BF0000 45056 own pid read write success or wait 1
    \KnownDlls\USER32.dll write and read and execute image 7E410000 593920 own pid read write success or wait 1
    \KnownDlls\GDI32.dll write and read and execute image 77F10000 299008 own pid read write success or wait 1
    \KnownDlls\ADVAPI32.dll write and read and execute image 77DD0000 634880 own pid read write success or wait 1
    \KnownDlls\RPCRT4.dll write and read and execute image 77E70000 602112 own pid read write success or wait 1
    \KnownDlls\Secur32.dll write and read and execute image 77FE0000 69632 own pid read write success or wait 1
    \NLS\NlsSectionCType read image 340000 12288 own pid readonly success or wait 1
    C:\WINDOWS\system32\imm32.dll write and read and execute commit 350000 110592 own pid execute success or wait 2
    C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
    Section loaded by program
    File Path Access Type Base Size Mapped to pid Protection Completion Count Source Address
    none query and write and read commit 380000 12288 own pid read write success or wait 8 402D5D
    none query and write and read commit 370000 12288 own pid read write success or wait 92 402D76
    C:\WINDOWS\system32\drivers\bios.sys query and write and read and execute and extend size commit 370000 8192 own pid readonly success or wait 2 401941
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp query and write and read and execute and extend size commit 370000 4096 own pid readonly success or wait 1 4014DC
    Memory Activities:
    Memory attributes changed
    PID Filepath Base Length New Protection Old Protection Completion Count Source Address
    992 C:\bb5511a6586ba04335712e6c65e83671.exe 400000 1000 page execute and read and write page readonly success or wait 1 402579
    992 C:\bb5511a6586ba04335712e6c65e83671.exe 401000 2000 page execute and read and write page execute read success or wait 1 402579
    992 C:\bb5511a6586ba04335712e6c65e83671.exe 403000 1000 page execute and read and write page readonly success or wait 1 402579
    992 C:\bb5511a6586ba04335712e6c65e83671.exe 404000 1000 page execute and read and write page write copy success or wait 1 402579
    992 C:\bb5511a6586ba04335712e6c65e83671.exe 405000 1D000 page execute and read and write page readonly success or wait 1 402579
    System Activities:
    System information queried
    System info class Completion Count Source Address
    ProcessInformation success or wait 1 402D5D
    ProcessInformation success or wait 1 402D5D
    ProcessInformation success or wait 1 402D5D
    ProcessInformation success or wait 1 402D5D
    Chronological sections
    Operation Data Completion Time
    Section loaded Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: image Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid success or wait 1579573038
    Section loaded Path: \NLS\NlsSectionUnicode Access: read Type: image Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pid success or wait 1579603962
    Section loaded Path: \NLS\NlsSectionLocale Access: read Type: image Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pid success or wait 1579608010
    Section loaded Path: \NLS\NlsSectionSortkey Access: query and read Type: image Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pid success or wait 1579610396
    Section loaded Path: \NLS\NlsSectionSortTbls Access: read Type: image Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pid success or wait 1579611762
    Section loaded Path: \KnownDlls\MSVCRT.dll Access: write and read and execute Type: image Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid success or wait 1579624672
    Section loaded Path: C:\WINDOWS\system32\psapi.dll Access: query and write and read and execute Type: image Baseaddress: 76BF0000 Size: 45056 Protection: read write Mapped to pid: own pid success or wait 1579640028
    Section loaded Path: \KnownDlls\USER32.dll Access: write and read and execute Type: image Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid success or wait 1579682499
    Section loaded Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: image Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid success or wait 1579686097
    Section loaded Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: image Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid success or wait 1579709670
    Section loaded Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: image Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid success or wait 1579717399
    Section loaded Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: image Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid success or wait 1579726115
    Section loaded Path: \NLS\NlsSectionCType Access: read Type: image Baseaddress: 340000 Size: 12288 Protection: readonly Mapped to pid: own pid success or wait 1579753181
    Section loaded Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 110592 Protection: execute Mapped to pid: own pid success or wait 1579778166
    Section loaded Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 110592 Protection: execute Mapped to pid: own pid success or wait 1579784519
    Section loaded Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid success or wait 1579789095
    Memory attributes changed PID: 992 Path: C:\bb5511a6586ba04335712e6c65e83671.exe Base: 400000 Length: 1000 New Protection: page execute and read and write New Protection: page readonly success or wait 1579930551
    Memory attributes changed PID: 992 Path: C:\bb5511a6586ba04335712e6c65e83671.exe Base: 401000 Length: 2000 New Protection: page execute and read and write New Protection: page execute read success or wait 1579931262
    Memory attributes changed PID: 992 Path: C:\bb5511a6586ba04335712e6c65e83671.exe Base: 403000 Length: 1000 New Protection: page execute and read and write New Protection: page readonly success or wait 1579931965
    Memory attributes changed PID: 992 Path: C:\bb5511a6586ba04335712e6c65e83671.exe Base: 404000 Length: 1000 New Protection: page execute and read and write New Protection: page write copy success or wait 1579932625
    Memory attributes changed PID: 992 Path: C:\bb5511a6586ba04335712e6c65e83671.exe Base: 405000 Length: 1D000 New Protection: page execute and read and write New Protection: page readonly success or wait 1579934256
    System info queried Type: ProcessInformation success or wait 1579940116
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579952641
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579953619
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579956134
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579958453
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579959424
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579960371
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579961296
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579962243
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579963427
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579964378
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579965619
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579966982
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579968449
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579969689
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579970928
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579972286
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579973536
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579975217
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579976467
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579981482
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579982777
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579984018
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579987951
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579989344
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1579990895
    System info queried Type: ProcessInformation success or wait 1579992432
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580004928
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580005882
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580008243
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580009221
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580010164
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580011250
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580012233
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580013175
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580014114
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580015307
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580016558
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580017796
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580019033
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580020267
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580021610
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580022851
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580024087
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580025720
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580027047
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580028286
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580029523
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580030898
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580032211
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580033468
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580037668
    File created Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: false success or wait 1580061630
    File write Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Offset: none Length: 5632 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 success or wait 1580162013
    File moved New path: C:\WINDOWS\system32\drivers\bios.sys Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp success or wait 1580193352
    File opened Path: MyDeviceDriver Access: read attributes and synchronize and generic read and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: false 12FAD0 1580270320
    System info queried Type: ProcessInformation success or wait 1580271835
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580308470
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580309433
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580315644
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580329429
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580330431
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 370000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580331377
    System info queried Type: ProcessInformation success or wait 1580399536
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580411952
    Section loaded Path: none Access: query and write and read Type: commit Baseaddress: 380000 Size: 12288 Protection: read write Mapped to pid: own pid success or wait 1580415034
    File moved New path: C:\WINDOWS\system32\drivers\beep.sys.bak Path: C:\WINDOWS\system32\drivers\beep.sys success or wait 1580543455
    File copied From: C:\WINDOWS\system32\drivers\bios.sys to: C:\WINDOWS\system32\drivers\bios.sys1 success or wait 1580720313
    Section loaded Path: C:\WINDOWS\system32\drivers\bios.sys Access: query and write and read and execute and extend size Type: commit Baseaddress: 370000 Size: 8192 Protection: readonly Mapped to pid: own pid success or wait 1580846748
    File copied From: C:\WINDOWS\system32\drivers\bios.sys to: C:\WINDOWS\system32\drivers\bios.sys2 success or wait 1580907938
    Section loaded Path: C:\WINDOWS\system32\drivers\bios.sys Access: query and write and read and execute and extend size Type: commit Baseaddress: 370000 Size: 8192 Protection: readonly Mapped to pid: own pid success or wait 1581020003
    File moved New path: C:\WINDOWS\system32\drivers\beep.sys Path: C:\WINDOWS\system32\drivers\bios.sys1 success or wait 1581134316
    File moved New path: C:\WINDOWS\system32\dllcache\beep.sysba Path: C:\WINDOWS\system32\drivers\bios.sys2 success or wait 1586413102
    File deleted Path: C:\WINDOWS\system32\drivers\beep.sys success or wait 1587000305
    File moved New path: C:\WINDOWS\system32\drivers\beep.sys Path: C:\WINDOWS\system32\drivers\beep.sys.bak success or wait 1587020174
    File deleted Path: C:\WINDOWS\system32\drivers\bios.sys success or wait 1587050490
    File opened Path: Bios Access: read attributes and synchronize and generic read and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: true success or wait 1587068014
    File created Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: false success or wait 1587069173
    File write Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Offset: none Length: 2688 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 C8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 success or wait 1587100717
    File copied From: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp to: c:\my.sys success or wait 1587105830
    Section loaded Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Access: query and write and read and execute and extend size Type: commit Baseaddress: 370000 Size: 4096 Protection: readonly Mapped to pid: own pid success or wait 1587128843
    File deleted Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp success or wait 1587133981
    File created Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Access: read data or list directory and write data or add file and append data or add subdirectory or create pipe instance and read ea and write ea and execute or traverse and delete child and read attributes and write attributes and delete and read control and write dac and write owner and synchronize Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: false success or wait 1587144908
    File write Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp Offset: none Length: 7680 Value: 55 AA 0F E9 4E 00 00 00 00 00 00 00 00 6A 00 00 00 00 00 00 00 00 00 00 1C 00 34 00 50 43 49 52 EC 10 39 81 00 00 18 00 00 02 00 00 08 00 01 02 00 80 00 00 24 50 6E 50 01 02 00 00 00 65 00 00 00 00 00 00 00 00 02 00 00 64 00 00 00 00 00 00 00 00 00 00 9C 66 60 06 1E FC E8 00 1C 33 C0 8E D0 BC 00 7C success or wait 1587160482
    File moved New path: C:\WINDOWS\system32\drivers\bios.sys Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE0F5.tmp success or wait 1587165822
    File opened Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom Access: read attributes and synchronize and generic read and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: false success or wait 1587172943
    File read Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom Offset: none Length: 7680 Value: 55 AA 0F E9 4E 00 00 00 00 00 00 00 00 6A 00 00 00 00 00 00 00 00 00 00 1C 00 34 00 50 43 49 52 EC 10 39 81 00 00 18 00 00 02 00 00 08 00 01 02 00 80 00 00 24 50 6E 50 01 02 00 00 00 65 00 00 00 00 00 00 00 00 02 00 00 64 00 00 00 00 00 00 00 00 00 00 9C 66 60 06 1E FC E8 00 1C 33 C0 8E D0 BC 00 7C success or wait 1587173897
    Privilege adjusted Privilege: Security On or off: on success or wait 1587187516
    File opened Path: PHYSICALDRIVE0 Access: read attributes and synchronize and generic read and generic write Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: false success or wait 1587187729
    File other operation Disposition: PositionInformation Data : Offset: 0 Path: \Device\Harddisk0\DR0 success or wait 1587193961
    File read Path: \Device\Harddisk0\DR0 Offset: none Length: 512 Value: 33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C success or wait 1587195636
    File other operation Disposition: PositionInformation Data : Offset: 0 Path: \Device\Harddisk0\DR0 success or wait 1587196869
    File write Path: \Device\Harddisk0\DR0 Offset: none Length: 7168 Value: 33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC 50 BE 00 7C BF 00 06 B9 00 02 F3 A4 BF 1E 06 57 CB B4 41 B2 80 BB AA 55 CD 13 81 FB 55 AA 75 30 F6 C1 01 74 2B BE 00 08 C7 04 10 00 C7 44 02 06 00 C7 44 04 00 7C C7 44 06 00 00 C6 44 08 01 B9 07 00 BF 09 08 C6 05 00 47 E2 FA B8 00 42 EB 0B B8 06 02 BB 00 7C B9 success or wait 1587200497
    File deleted Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hook.rom success or wait 1587206813
    Analysis File: Beep.SYS PID: 4 Parent PID: -1
    Sections
    General
    Start time: 04:47:02
    Start date: 16/09/2011
    Path: C:\WINDOWS\System32\Drivers\Beep.SYS
    Commandline: not known
    Imagebase:
    File size: 5632 bytes
    MD5 hash: CDDE77A83EA545C14B22C32CA9655BDD
    File Activities:
    File opened
    File Path Access Options Content overwritten Completion Count Source Address
    C:\WINDOWS\AppPatch\drvmain.sdb generic read no options success or wait 1
    Other file operations
    File Path Disposition Data Ascii Data Completion Count Source Address
    \Device\Bios SymbolicLinkCreate Symbolic link name: \DosDevices\Bios success or wait 1
    Section Activities:
    Section loaded by Windows
    File Path Access Type Base Size Mapped to pid Protection Completion Count
    Section loaded by program
    File Path Access Type Base Size Mapped to pid Protection Completion Count Source Address
    C:\WINDOWS\AppPatch\drvmain.sdb read commit 40000 12288 own pid readonly success or wait 1
    Registry Activities:
    Key value set
    Key Path Name Type Data Completion Count Source Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BEEP\0000\Control ActiveService String Beep success or wait 1
    Key value queried
    Key Path Name Completion Count Source Address
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Beep\Enum Count success or wait 1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BEEP\0000 ConfigFlags success or wait 1
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Beep ImagePath object name not found 1
    Driver Activities:
    Device created
    Device name Device type Completion Count Source Address
    \Device\Bios unknown success or wait 1
    Chronological sections
    Operation Data Completion Time
    Key value queried Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Beep\Enum Name: Count success or wait 1586973435
    Key value queried Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BEEP\0000 Name: ConfigFlags success or wait 1586974179
    Key value set Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BEEP\0000\Control Name: ActiveService Type: String Data: Beep success or wait 1586975184
    Key value queried Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Beep Name: ImagePath object name not found 1586975394
    File opened Path: C:\WINDOWS\AppPatch\drvmain.sdb Access: generic read Options: no options success or wait 1586975602
    Section loaded Path: C:\WINDOWS\AppPatch\drvmain.sdb Access: read Type: commit Baseaddress: 40000 Size: 12288 Protection: readonly Mapped to pid: own pid success or wait 1586976392
    Device created Device Name: \Device\Bios Device Type: unknown success or wait 1586977555
    Symbolic link created Symbolic link name: \DosDevices\Bios File path: \Device\Bios success or wait 1586977829
    Copyright 2011 Joe Security | All rights reserved | www.joesecurity.org | This page is optimized for firefox - 1024x786