Analysis ID: 25113
Start time: 13:05:09
Start date: 29/10/2012
Overall analysis duration: 0h 6m 27s
Sample file name: long sleep 2s
Cookbook file name: default.jbs
Analysis system description: XP SP3 (Office 2003 SP2, Java 1.6.0, Acrobat Reader 9.3.4, Internet Explorer 8)
Number of analysed new started processes analysed: 6
Number of new started drivers analysed: 0
Number of existing processes analysed: 0
Number of existing drivers analysed: 0
Number of injected processes analysed: 0
  • Too many NtProtectVirtualMemory calls (excessive behavior)

Matching Signatures

Spawns processes
Binary may include packed or crypted data
Creates files inside the system directory
Drops PE files
May tried to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
Contains long sleeps (>= 3 min)


  • system is xp
  • long sleep 2s.exe (PID: 1764 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
    • cmd.exe (PID: 1492 MD5: 6D778E0F95447E6546553EEEA709D03C)
    • explorer.exe (PID: 1696 MD5: 12896823FB95BFB3DC9B46BCAEDC9923)
    • cmd.exe (PID: 260 MD5: 6D778E0F95447E6546553EEEA709D03C)
      • smss.exe (PID: 2036 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
  • smss.exe (PID: 988 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
  • cleanup

Created / dropped Files

File Path MD5
C:\WINDOWS\system32\LogFiles\smss.exe 4627B559FD60FCBF5DEF3C3DA6796C37
\net\NtControlPipe20 1762360A5F893647DA17132504911925

Static File Info

File type: PE32 executable (GUI) Intel 80386, for MS Windows
File name: long sleep 2s
File size: 69632
MD5: 8ebd97ee5f259cb2f1b38da1f1040cf0
SHA1: 0d625e128878c81000c51a4164278a4d82dbec38
SHA256: fbd61f2a302779e6946895fbe111534f016dc232495c2146edcbfa72b982faa3
SHA512: b670d450e5983ea1f6ddbee37fc3eb3d870a6631b27a4bb5cad1790822edf2d32aebab99400e5a0021f6bc56fca760c301908922a5441973f48e41dba1ce9c42

Static PE Info

Entrypoint: 0x14006d83
Entrypoint Section: .text
Imagebase: 0x14000000
Subsystem: windows gui
DLL Characteristics:
Time Stamp: 0x4B236366 [Sat Dec 12 09:33:26 2009 UTC]
TLS Callbacks:
Name RVA Size Type Language Country
RT_ICON 0xf190 0xea8 data Chinese China
RT_ICON 0x10038 0x8a8 data Chinese China
RT_ICON 0x108e0 0x6c8 data Chinese China
RT_ICON 0x10fa8 0x568 GLS_BINARY_LSB_FIRST Chinese China
RT_GROUP_ICON 0x11510 0x3e MS Windows icon resource - 4 icons, 48x48, 256-colors Chinese China
RT_VERSION 0x11550 0x40c data Chinese China
DLL Import
KERNEL32.dll GetLogicalDrives, GetSystemDirectoryA, GetCurrentProcessId, GetTickCount, WaitForSingleObject, CreateProcessA, TerminateProcess, GetExitCodeProcess, ReadFile, FindClose, FindNextFileA, FindFirstFileA, GetVersionExA, GlobalMemoryStatus, Beep, GetLogicalDriveStringsA, GetDriveTypeA, GetLocalTime, Process32Next, Process32First, CreateToolhelp32Snapshot, GetLastError, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx, VirtualFreeEx, OpenProcess, GetModuleHandleA, SetStdHandle, LoadLibraryA, GetProcAddress, GetVolumeInformationA, GetPrivateProfileStringA, GetFileSize, DeleteFileA, SetFilePointer, CreateFileA, WriteFile, CloseHandle, GetVersion, GetCurrentProcess, CopyFileA, ExitProcess, GetCurrentThreadId, GetModuleFileNameA, GetWindowsDirectoryA, WinExec, Sleep, SetFileAttributesA, CreateThread, HeapReAlloc, VirtualAlloc, HeapAlloc, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, MultiByteToWideChar, RtlUnwind, HeapFree, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetStartupInfoA, GetCommandLineA, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, FlushFileBuffers
USER32.dll PostThreadMessageA, ExitWindowsEx
ADVAPI32.dll RegisterServiceCtrlHandlerA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, ChangeServiceConfigA, ControlService, DeleteService, OpenServiceA, SetServiceStatus, OpenSCManagerA, CreateServiceA, CloseServiceHandle, ChangeServiceConfig2A, StartServiceA, StartServiceCtrlDispatcherA
WS2_32.dll WSASocketA
SHLWAPI.dll PathFileExistsA
Name Virtual Address Virtual Size Raw Size Entropy
.text 0x1000 0x93f8 0xa000 6.13551319499
.rdata 0xb000 0xf76 0x1000 5.29189470492
.data 0xc000 0x28bc 0x2000 2.58448393238
.rsrc 0xf000 0x18000 0x3000 3.54133462508
Version Infos
Description Data
LegalCopyright (C) 1988-2009 Microsoft Corp. All rights reserved.
InternalName NTservice
FileVersion 5, 3, 2600, 2180
CompanyName Microsoft Corporation
ProductName Microsoft(R) Windows(R) Operating System
ProductVersion 5, 3, 2600, 2180
FileDescription Windows NT Security Support
OriginalFilename services.exe
Translation 0x0804 0x04b0
Possible Origin
Language of compilation system Country where language is spoken Map
Chinese China

String Analysis

VM Artifacts
String value Source
\??\C:\WINDOWS\system32\VBoxService.e cmd.exe
\??\C:\WINDOWS\system32\VBoxTray.e long sleep 2s.exe, cmd.exe

Network Behavior

No network behavior found

Code Manipulation Behavior

System Behavior

Start time: 09:39:46
Start date: 24/01/2012
Path: C:\long sleep 2s.exe
Wow64 process (32bit): false
Commandline: unknown
Imagebase: 0x14000000
File size: 69632 bytes
MD5 hash: 8EBD97EE5F259CB2F1B38DA1F1040CF0

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
C:\long sleep 2s.exe read attributes and synchronize and generic read sequential only and synchronous io non alert and non directory file and open reparse point success or wait 10 140012F7 CopyFileA
File Path Access Attributes Options Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles\smss.exe read attributes and delete and synchronize and generic write archive sequential only and synchronous io non alert and non directory file success or wait 10 140012F7 CopyFileA
File Path Offset Length Value Completion Count Source Address Symbol
File Path Disposition File Mask Completion Count Source Address Symbol
File Path Disposition Data Ascii Data Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles\smss.exe BasicInformation Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write Time: 01:00 01-01-1601 Change Time: 01:00 01-01-1601 File Attributes: readony and system and directory and archive and temporary success or wait 1 14001308 SetFileAttributesA

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 260000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 280000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2D0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 320000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WS2_32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2_32.dll query and write and read and execute image 71AB0000 94208 own pid read write success or wait 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\WS2HELP.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2help.dll query and write and read and execute image 71AA0000 32768 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 400000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 400000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 840000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and write and read and execute and extend size image 840000 12288 own pid readonly success or wait 1
\BaseNamedObjects\ShimSharedMemory write unknown 960000 57344 own pid read write success or wait 1
C:\WINDOWS\system32\apphelp.dll write and read and execute commit 970000 126976 own pid execute success or wait 1
C:\WINDOWS\system32\apphelp.dll query and write and read and execute image 77B40000 139264 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 970000 1208320 own pid readonly success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AA0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AA0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AA0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AA0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit 970000 389120 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe query and write and read and execute and extend size image 970000 389120 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 980000 1208320 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe write and read and execute commit AB0000 1036288 own pid execute success or wait 1
C:\WINDOWS\explorer.exe query and read commit AB0000 1036288 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe write and read and execute commit AB0000 1036288 own pid execute success or wait 1
C:\WINDOWS\explorer.exe query and read commit AB0000 1036288 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe query and read commit 980000 1036288 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and write and read and execute and extend size image 980000 69632 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 980000 1208320 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AB0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AB0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AB0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AB0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit 980000 389120 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol

Process Activites

PID Filepath Cmdline Flags Completion Count Source Address Symbol
1492 C:\WINDOWS\system32\cmd.exe cmd /c md C:\WINDOWS\system32\LogFiles none success or wait 1 1400113E WinExec
1696 C:\WINDOWS\explorer.exe explorer C:\ none success or wait 1 14001476 WinExec
260 C:\WINDOWS\system32\cmd.exe cmd /c C:\WINDOWS\system32\LogFiles\smss.exe none success or wait 1 14001332 WinExec
PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol
1764 C:\long sleep 2s.exe success or wait 1 14006058 ExitProcess

Thread Activites

TID PID EIP EAX (Usermode EIP) Filepath Completion Count Source Address Symbol
TID PID Path Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Protection Completion Count Source Address Symbol
1764 C:\long sleep 2s.exe 850000 12FF1C page read and write success or wait 1 1400813A HeapCreate
1764 C:\long sleep 2s.exe 850000 12FF20 page read and write success or wait 1 1400813A HeapCreate
1764 C:\long sleep 2s.exe 860000 12FE78 page read and write success or wait 1 140098EB VirtualAlloc
1764 C:\long sleep 2s.exe 860000 12FE68 page read and write success or wait 1 14009977 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:47 0 1 0
09:39:48 0 1 0

System Activites

System info class Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 850000 Length: 12FF1C Allocation Type: unknown Protection: page read and write success or wait 525924732
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 850000 Length: 12FF20 Allocation Type: unknown Protection: page read and write success or wait 525925069
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 860000 Length: 12FE78 Allocation Type: unknown Protection: page read and write success or wait 525929215
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 860000 Length: 12FE68 Allocation Type: unknown Protection: page read and write success or wait 525929599
Process created PID: 1492 Path: C:\WINDOWS\system32\cmd.exe Cmdline: cmd /c md C:\WINDOWS\system32\LogFiles Createflags: none success or wait 526245228
Process created PID: 1696 Path: C:\WINDOWS\explorer.exe Cmdline: explorer C:\ Createflags: none success or wait 527026603
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 530689848
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 530693545
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531089668
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531098322
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531147099
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531147891
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531196435
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531197320
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531243659
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531244427
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531303527
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531304016
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531357896
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531358690
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531408728
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531413725
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531463745
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531464539
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531514287
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531514785
File other op Path: C:\WINDOWS\system32\LogFiles\smss.exe New path: Disposition: BasicInformation Data : Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write Time: 01:00 01-01-1601 Change Time: 01:00 01-01-1601 File Attributes: readony and system and directory and archive and temporary success or wait 531562763
Process created PID: 260 Path: C:\WINDOWS\system32\cmd.exe Cmdline: cmd /c C:\WINDOWS\system32\LogFiles\smss.exe Createflags: none success or wait 531606008
Process terminated PID: 1764 Path: C:\long sleep 2s.exe success or wait 531704926
Start time: 09:39:47
Start date: 24/01/2012
Path: C:\WINDOWS\system32\cmd.exe
Wow64 process (32bit): false
Commandline: cmd /c md C:\WINDOWS\system32\LogFiles
Imagebase: 0x4ad00000
File size: 389120 bytes
MD5 hash: 6D778E0F95447E6546553EEEA709D03C

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Access Attributes Options Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles read data or list directory and synchronize normal directory file and synchronous io non alert and open for backup ident success or wait 1 4AD0B2AC CreateDirectoryW
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 270000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 290000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2E0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 330000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 340000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 490000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 970000 8462336 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 970000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 440000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 440000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 440000 4096 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit 970000 618496 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor PathCompletionChar success or wait 1 4AD04B37 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor AutoRun success or wait 1 4AD04BB8 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor PathCompletionChar object name not found 1 4AD04B37 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor AutoRun object name not found 1 4AD04BB8 RegQueryValueExW

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Protection Completion Count Source Address Symbol
1492 C:\WINDOWS\system32\cmd.exe 970000 13FE10 page read and write success or wait 1 4AD04578 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:47 1 0 1

System Activites

System info class Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DisableUNCCheck object name not found 528855744
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: EnableExtensions success or wait 528857038
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DelayedExpansion object name not found 528857628
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DefaultColor success or wait 528861213
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: CompletionChar success or wait 528862432
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: PathCompletionChar success or wait 528863017
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: AutoRun success or wait 528867032
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DisableUNCCheck object name not found 528868804
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: EnableExtensions success or wait 528870791
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DelayedExpansion object name not found 528872495
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DefaultColor success or wait 528873082
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: CompletionChar success or wait 528873664
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: PathCompletionChar object name not found 528874288
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: AutoRun object name not found 528874774
Memory allocated PID: 1492 Path: C:\WINDOWS\system32\cmd.exe Base: 970000 Length: 13FE10 Allocation Type: unknown Protection: page read and write success or wait 528887297
File created Path: C:\WINDOWS\system32\LogFiles Access: read data or list directory and synchronize Options: directory file and synchronous io non alert and open for backup ident Attributes: normal Content Overwritten: null success or wait 528903119
Start time: 09:39:47
Start date: 24/01/2012
Path: C:\WINDOWS\explorer.exe
Wow64 process (32bit): false
Commandline: explorer C:\
Imagebase: 0x7c900000
File size: 1033728 bytes
MD5 hash: 12896823FB95BFB3DC9B46BCAEDC9923

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Offset Length Value Completion Count Source Address Symbol
File Path Offset Length Completion Count Source Address Symbol
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 1B0000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 1D0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 220000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 270000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\BROWSEUI.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\browseui.dll query and write and read and execute image 75F80000 1036288 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\SHDOCVW.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shdocvw.dll query and write and read and execute image 7E290000 1511424 own pid read write success or wait 1
\KnownDlls\CRYPT32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\crypt32.dll query and write and read and execute image 77A80000 610304 own pid read write success or wait 1
\KnownDlls\MSASN1.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msasn1.dll query and write and read and execute image 77B20000 73728 own pid read write success or wait 1
\KnownDlls\CRYPTUI.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\cryptui.dll query and write and read and execute image 754D0000 524288 own pid read write success or wait 1
\KnownDlls\NETAPI32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\netapi32.dll query and write and read and execute image 5B860000 348160 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\WININET.dll write and read and execute unknown 3D930000 942080 own pid read write success or wait 1
\KnownDlls\Normaliz.dll write and read and execute unknown 400000 36864 own pid read write success or wait 1
\KnownDlls\urlmon.dll write and read and execute unknown 78130000 1257472 own pid read write success or wait 1
\KnownDlls\iertutil.dll write and read and execute unknown 3DFD0000 2002944 own pid read write success or wait 1
\KnownDlls\WINTRUST.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\wintrust.dll query and write and read and execute image 76C30000 188416 own pid read write success or wait 1
\KnownDlls\IMAGEHLP.dll write and read and execute unknown 76C90000 163840 own pid read write success or wait 1
\KnownDlls\WLDAP32.dll write and read and execute unknown 76F60000 180224 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 290000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 410000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 410000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 3E0000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 360000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 360000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\browseui.dll read commit 860000 1028096 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 860000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 390000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 390000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 390000 4096 own pid readonly success or wait 1
\KnownDlls\RichEd20.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\riched20.dll query and write and read and execute image 74E30000 446464 own pid read write success or wait 1
C:\WINDOWS\system32\shdocvw.dll read commit AA0000 1499136 own pid readonly success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 1100000 8462336 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit AC0000 618496 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe read commit B70000 1036288 own pid readonly success or wait 1
\KnownDlls\SETUPAPI.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\setupapi.dll query and write and read and execute image 77920000 995328 own pid read write success or wait 1
unknown query and write and read commit B50000 4096 own pid read write success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol
1696 C:\WINDOWS\explorer.exe success or wait 1 102340F ExitProcess

Thread Activites

TID PID EIP EAX (Usermode EIP) Filepath Completion Count Source Address Symbol
TID PID Path Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Protection Completion Count Source Address Symbol
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:47 0 0 0

System Activites

System info class Completion Count Source Address Symbol

Timing Activites

Time Completion Count Source Address Symbol

Windows UI Activites

HWND Message LParam WParam Completion Count Source Address Symbol

Process Token Activites

Status Privilege Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Process terminated PID: 1696 Path: C:\WINDOWS\explorer.exe success or wait 530212507
Start time: 09:39:48
Start date: 24/01/2012
Path: C:\WINDOWS\system32\cmd.exe
Wow64 process (32bit): false
Commandline: cmd /c C:\WINDOWS\system32\LogFiles\smss.exe
Imagebase: 0x4ad00000
File size: 389120 bytes
MD5 hash: 6D778E0F95447E6546553EEEA709D03C

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Disposition File Mask Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles BothDirectoryInformation smss.exe success or wait 5 4AD01B4B FindFirstFileW
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 270000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 290000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2E0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 330000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 340000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 490000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 970000 8462336 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 970000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 440000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 440000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 440000 4096 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit 970000 618496 own pid readonly success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe query and write and read and execute and extend size image 970000 618496 own pid readonly success or wait 1
\BaseNamedObjects\ShimSharedMemory write unknown 980000 57344 own pid read write success or wait 1
C:\WINDOWS\system32\apphelp.dll write and read and execute commit 990000 126976 own pid execute success or wait 1
C:\WINDOWS\system32\apphelp.dll query and write and read and execute image 77B40000 139264 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 990000 1208320 own pid readonly success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe write and read and execute commit AC0000 69632 own pid execute success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe query and read commit AC0000 69632 own pid readonly success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe write and read and execute commit AC0000 69632 own pid execute success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe query and read commit AC0000 69632 own pid readonly success or wait 1
C:\WINDOWS\system32\LogFiles\smss.exe query and read commit 990000 69632 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor PathCompletionChar success or wait 1 4AD04B37 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor AutoRun success or wait 1 4AD04BB8 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor PathCompletionChar object name not found 1 4AD04B37 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor AutoRun object name not found 1 4AD04BB8 RegQueryValueExW

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Filepath Cmdline Flags Completion Count Source Address Symbol
2036 C:\WINDOWS\system32\LogFiles\smss.exe C:\WINDOWS\system32\LogFiles\smss.exe suspended success or wait 1 4AD031C5 CreateProcessW
PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol

Thread Activites

TID PID EIP EAX (Usermode EIP) Filepath Completion Count Source Address Symbol
TID PID Path Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Protection Completion Count Source Address Symbol
260 C:\WINDOWS\system32\cmd.exe 970000 13FE10 page read and write success or wait 1 4AD04578 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol

System Activites

System info class Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DisableUNCCheck object name not found 532083435
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: EnableExtensions success or wait 532083659
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DelayedExpansion object name not found 532083951
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: DefaultColor success or wait 532084196
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: CompletionChar success or wait 532084404
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: PathCompletionChar success or wait 532085098
Key value queried Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor Name: AutoRun success or wait 532085317
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DisableUNCCheck object name not found 532086607
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: EnableExtensions success or wait 532087116
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DelayedExpansion object name not found 532087333
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: DefaultColor success or wait 532087717
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: CompletionChar success or wait 532087930
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: PathCompletionChar object name not found 532088139
Key value queried Path: HKEY_USERS\Software\Microsoft\Command Processor Name: AutoRun object name not found 532088384
Memory allocated PID: 260 Path: C:\WINDOWS\system32\cmd.exe Base: 970000 Length: 13FE10 Allocation Type: unknown Protection: page read and write success or wait 532090149
Directory Information Queried Path: C:\WINDOWS\system32\LogFilesDisposition: BothDirectoryInformation Filemask: smss.exe success or wait 532097919
Directory Information Queried Path: C:\WINDOWS\system32\LogFilesDisposition: BothDirectoryInformation Filemask: smss.exe success or wait 532207215
Directory Information Queried Path: C:\WINDOWS\system32\LogFilesDisposition: BothDirectoryInformation Filemask: smss.exe success or wait 532213956
Directory Information Queried Path: C:\WINDOWS\system32\LogFilesDisposition: BothDirectoryInformation Filemask: smss.exe success or wait 532246258
Directory Information Queried Path: C:\WINDOWS\system32\LogFilesDisposition: BothDirectoryInformation Filemask: smss.exe success or wait 532298913
Process created PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe Cmdline: C:\WINDOWS\system32\LogFiles\smss.exe Createflags: suspended success or wait 532309877
Start time: 09:39:48
Start date: 24/01/2012
Path: C:\WINDOWS\system32\LogFiles\smss.exe
Wow64 process (32bit): false
Commandline: C:\WINDOWS\system32\LogFiles\smss.exe
Imagebase: 0x77dd0000
File size: 69632 bytes
MD5 hash: 8EBD97EE5F259CB2F1B38DA1F1040CF0

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 270000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 290000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2E0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 330000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WS2_32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2_32.dll query and write and read and execute image 71AB0000 94208 own pid read write success or wait 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\WS2HELP.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2help.dll query and write and read and execute image 71AA0000 32768 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 340000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 490000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 970000 8462336 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 970000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 440000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 440000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 440000 4096 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit 970000 618496 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol
2036 C:\WINDOWS\system32\LogFiles\smss.exe success or wait 1 14006058 ExitProcess

Memory Activites

PID Filepath Base Length Protection Completion Count Source Address Symbol
2036 C:\WINDOWS\system32\LogFiles\smss.exe 970000 13FF1C page read and write success or wait 1 1400813A HeapCreate
2036 C:\WINDOWS\system32\LogFiles\smss.exe 970000 13FF20 page read and write success or wait 1 1400813A HeapCreate
2036 C:\WINDOWS\system32\LogFiles\smss.exe 980000 13FE78 page read and write success or wait 1 140098EB VirtualAlloc
2036 C:\WINDOWS\system32\LogFiles\smss.exe 980000 13FE68 page read and write success or wait 1 14009977 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol

System Activites

System info class Completion Count Source Address Symbol

Timing Activites

Time Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Memory allocated PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 970000 Length: 13FF1C Allocation Type: unknown Protection: page read and write success or wait 532827446
Memory allocated PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 970000 Length: 13FF20 Allocation Type: unknown Protection: page read and write success or wait 532827571
Memory allocated PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 980000 Length: 13FE78 Allocation Type: unknown Protection: page read and write success or wait 532828406
Memory allocated PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 980000 Length: 13FE68 Allocation Type: unknown Protection: page read and write success or wait 532828548
Process terminated PID: 2036 Path: C:\WINDOWS\system32\LogFiles\smss.exe success or wait 533880917
Start time: 09:39:48
Start date: 24/01/2012
Path: C:\WINDOWS\system32\LogFiles\smss.exe
Wow64 process (32bit): false
Commandline: unknown
Imagebase: 0x71aa0000
File size: 69632 bytes
MD5 hash: 8EBD97EE5F259CB2F1B38DA1F1040CF0

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Offset Length Value Completion Count Source Address Symbol
File Path Offset Length Completion Count Source Address Symbol
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 270000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 290000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2E0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 330000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WS2_32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2_32.dll query and write and read and execute image 71AB0000 94208 own pid read write success or wait 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\WS2HELP.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2help.dll query and write and read and execute image 71AA0000 32768 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 340000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 490000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 6F0000 8462336 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 6F0000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 440000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 440000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 440000 4096 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit 6F0000 618496 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Process info class Completion Count Source Address Symbol

Thread Activites

TID PID EIP EAX (Usermode EIP) Filepath Completion Count Source Address Symbol
TID PID Path Completion Count Source Address Symbol
TID Delay Completion Count Source Address Symbol
1268 -360s unknown 1 1400191E Sleep

Memory Activites

PID Filepath Base Length Protection Completion Count Source Address Symbol
988 C:\WINDOWS\system32\LogFiles\smss.exe 6F0000 13FF1C page read and write success or wait 1 1400813A HeapCreate
988 C:\WINDOWS\system32\LogFiles\smss.exe 6F0000 13FF20 page read and write success or wait 1 1400813A HeapCreate
988 C:\WINDOWS\system32\LogFiles\smss.exe 700000 13FE78 page read and write success or wait 1 140098EB VirtualAlloc
988 C:\WINDOWS\system32\LogFiles\smss.exe 700000 13FE68 page read and write success or wait 1 14009977 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:49 1 2 1

System Activites

System info class Completion Count Source Address Symbol

Timing Activites

Time Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Memory allocated PID: 988 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 6F0000 Length: 13FF1C Allocation Type: unknown Protection: page read and write success or wait 533740582
Memory allocated PID: 988 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 6F0000 Length: 13FF20 Allocation Type: unknown Protection: page read and write success or wait 533740927
Memory allocated PID: 988 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 700000 Length: 13FE78 Allocation Type: unknown Protection: page read and write success or wait 533743927
Memory allocated PID: 988 Path: C:\WINDOWS\system32\LogFiles\smss.exe Base: 700000 Length: 13FE68 Allocation Type: unknown Protection: page read and write success or wait 533744281
Thread delayed Time: -360 TID: 1268 unknown 533853072