General Information

Analysis ID: 25113
Start time: 13:05:09
Start date: 29/10/2012
Overall analysis duration: 0h 6m 27s
Sample file name: long sleep 2s
Cookbook file name: default.jbs
Analysis system description: XP SP3 (Office 2003 SP2, Java 1.6.0, Acrobat Reader 9.3.4, Internet Explorer 8)
Number of analysed new started processes analysed: 6
Number of new started drivers analysed: 0
Number of existing processes analysed: 0
Number of existing drivers analysed: 0
Number of injected processes analysed: 0
Warnings:
  • Too many NtProtectVirtualMemory calls (excessive behavior)

Classification / Threat Score

Persistence, Installation, Boot Survival :
Hiding, Stealthiness, Detection and Removal Protection :
Security Solution / Mechanism bypass, termination and removal, Anti Debugging, VM Detection :
Spreading :
Exploiting :
Networking :
Data spying, Sniffing, Keylogging, Ebanking Fraud :

Matching Signatures

Spawns processes
Binary may include packed or crypted data
Creates files inside the system directory
Drops PE files
May tried to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
Contains long sleeps (>= 3 min)

Startup

  • system is xp
  • long sleep 2s.exe (PID: 1764 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
    • cmd.exe (PID: 1492 MD5: 6D778E0F95447E6546553EEEA709D03C)
    • explorer.exe (PID: 1696 MD5: 12896823FB95BFB3DC9B46BCAEDC9923)
    • cmd.exe (PID: 260 MD5: 6D778E0F95447E6546553EEEA709D03C)
      • smss.exe (PID: 2036 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
  • smss.exe (PID: 988 MD5: 8EBD97EE5F259CB2F1B38DA1F1040CF0)
  • cleanup

Created / dropped Files

File Path MD5
C:\WINDOWS\system32\LogFiles\smss.exe 4627B559FD60FCBF5DEF3C3DA6796C37
\net\NtControlPipe20 1762360A5F893647DA17132504911925

Contacted Domains

No contacted domains info

Contacted IPs

No contacted IP infos

Static File Info

File type: PE32 executable (GUI) Intel 80386, for MS Windows
File name: long sleep 2s
File size: 69632
MD5: 8ebd97ee5f259cb2f1b38da1f1040cf0
SHA1: 0d625e128878c81000c51a4164278a4d82dbec38
SHA256: fbd61f2a302779e6946895fbe111534f016dc232495c2146edcbfa72b982faa3
SHA512: b670d450e5983ea1f6ddbee37fc3eb3d870a6631b27a4bb5cad1790822edf2d32aebab99400e5a0021f6bc56fca760c301908922a5441973f48e41dba1ce9c42

Static PE Info

General
Entrypoint: 0x14006d83
Entrypoint Section: .text
Imagebase: 0x14000000
Subsystem: windows gui
Image File Characteristics: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
DLL Characteristics:
Time Stamp: 0x4B236366 [Sat Dec 12 09:33:26 2009 UTC]
TLS Callbacks:
Resources
Name RVA Size Type Language Country
RT_ICON 0xf190 0xea8 data Chinese China
RT_ICON 0x10038 0x8a8 data Chinese China
RT_ICON 0x108e0 0x6c8 data Chinese China
RT_ICON 0x10fa8 0x568 GLS_BINARY_LSB_FIRST Chinese China
RT_GROUP_ICON 0x11510 0x3e MS Windows icon resource - 4 icons, 48x48, 256-colors Chinese China
RT_VERSION 0x11550 0x40c data Chinese China
Imports
DLL Import
KERNEL32.dll GetLogicalDrives, GetSystemDirectoryA, GetCurrentProcessId, GetTickCount, WaitForSingleObject, CreateProcessA, TerminateProcess, GetExitCodeProcess, ReadFile, FindClose, FindNextFileA, FindFirstFileA, GetVersionExA, GlobalMemoryStatus, Beep, GetLogicalDriveStringsA, GetDriveTypeA, GetLocalTime, Process32Next, Process32First, CreateToolhelp32Snapshot, GetLastError, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx, VirtualFreeEx, OpenProcess, GetModuleHandleA, SetStdHandle, LoadLibraryA, GetProcAddress, GetVolumeInformationA, GetPrivateProfileStringA, GetFileSize, DeleteFileA, SetFilePointer, CreateFileA, WriteFile, CloseHandle, GetVersion, GetCurrentProcess, CopyFileA, ExitProcess, GetCurrentThreadId, GetModuleFileNameA, GetWindowsDirectoryA, WinExec, Sleep, SetFileAttributesA, CreateThread, HeapReAlloc, VirtualAlloc, HeapAlloc, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, MultiByteToWideChar, RtlUnwind, HeapFree, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetStartupInfoA, GetCommandLineA, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, FlushFileBuffers
USER32.dll PostThreadMessageA, ExitWindowsEx
ADVAPI32.dll RegisterServiceCtrlHandlerA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, ChangeServiceConfigA, ControlService, DeleteService, OpenServiceA, SetServiceStatus, OpenSCManagerA, CreateServiceA, CloseServiceHandle, ChangeServiceConfig2A, StartServiceA, StartServiceCtrlDispatcherA
WS2_32.dll WSASocketA
SHLWAPI.dll PathFileExistsA
Sections
Name Virtual Address Virtual Size Raw Size Entropy
.text 0x1000 0x93f8 0xa000 6.13551319499
.rdata 0xb000 0xf76 0x1000 5.29189470492
.data 0xc000 0x28bc 0x2000 2.58448393238
.rsrc 0xf000 0x18000 0x3000 3.54133462508
Version Infos
Description Data
LegalCopyright (C) 1988-2009 Microsoft Corp. All rights reserved.
InternalName NTservice
FileVersion 5, 3, 2600, 2180
CompanyName Microsoft Corporation
PrivateBuild
LegalTrademarks
Comments
ProductName Microsoft(R) Windows(R) Operating System
SpecialBuild
ProductVersion 5, 3, 2600, 2180
FileDescription Windows NT Security Support
OriginalFilename services.exe
Translation 0x0804 0x04b0
Possible Origin
Language of compilation system Country where language is spoken Map
Chinese China

String Analysis

VM Artifacts
String value Source
\??\C:\WINDOWS\system32\VBoxService.e cmd.exe
\??\C:\WINDOWS\system32\VBoxTray.e long sleep 2s.exe, cmd.exe

Network Behavior

No network behavior found

Code Manipulation Behavior

System Behavior

General
Start time: 09:39:46
Start date: 24/01/2012
Path: C:\long sleep 2s.exe
Wow64 process (32bit): false
Commandline: unknown
Imagebase: 0x14000000
File size: 69632 bytes
MD5 hash: 8EBD97EE5F259CB2F1B38DA1F1040CF0

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
C:\long sleep 2s.exe read attributes and synchronize and generic read sequential only and synchronous io non alert and non directory file and open reparse point success or wait 10 140012F7 CopyFileA
File Path Access Attributes Options Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles\smss.exe read attributes and delete and synchronize and generic write archive sequential only and synchronous io non alert and non directory file success or wait 10 140012F7 CopyFileA
File Path Offset Length Value Completion Count Source Address Symbol
File Path Disposition File Mask Completion Count Source Address Symbol
File Path Disposition Data Ascii Data Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles\smss.exe BasicInformation Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write Time: 01:00 01-01-1601 Change Time: 01:00 01-01-1601 File Attributes: readony and system and directory and archive and temporary success or wait 1 14001308 SetFileAttributesA

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 260000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 280000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2D0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 320000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WS2_32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2_32.dll query and write and read and execute image 71AB0000 94208 own pid read write success or wait 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\WS2HELP.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\ws2help.dll query and write and read and execute image 71AA0000 32768 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 400000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 400000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 840000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and write and read and execute and extend size image 840000 12288 own pid readonly success or wait 1
\BaseNamedObjects\ShimSharedMemory write unknown 960000 57344 own pid read write success or wait 1
C:\WINDOWS\system32\apphelp.dll write and read and execute commit 970000 126976 own pid execute success or wait 1
C:\WINDOWS\system32\apphelp.dll query and write and read and execute image 77B40000 139264 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 970000 1208320 own pid readonly success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AA0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AA0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AA0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AA0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit 970000 389120 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe query and write and read and execute and extend size image 970000 389120 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 980000 1208320 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe write and read and execute commit AB0000 1036288 own pid execute success or wait 1
C:\WINDOWS\explorer.exe query and read commit AB0000 1036288 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe write and read and execute commit AB0000 1036288 own pid execute success or wait 1
C:\WINDOWS\explorer.exe query and read commit AB0000 1036288 own pid readonly success or wait 1
C:\WINDOWS\explorer.exe query and read commit 980000 1036288 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\long sleep 2s.exe query and write and read and execute and extend size commit 980000 69632 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and write and read and execute and extend size image 980000 69632 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 980000 1208320 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AB0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AB0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe write and read and execute commit AB0000 389120 own pid execute success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit AB0000 389120 own pid readonly success or wait 1
C:\WINDOWS\system32\cmd.exe query and read commit 980000 389120 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol

Process Activites

PID Filepath Cmdline Flags Completion Count Source Address Symbol
1492 C:\WINDOWS\system32\cmd.exe cmd /c md C:\WINDOWS\system32\LogFiles none success or wait 1 1400113E WinExec
1696 C:\WINDOWS\explorer.exe explorer C:\ none success or wait 1 14001476 WinExec
260 C:\WINDOWS\system32\cmd.exe cmd /c C:\WINDOWS\system32\LogFiles\smss.exe none success or wait 1 14001332 WinExec
PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol
1764 C:\long sleep 2s.exe success or wait 1 14006058 ExitProcess

Thread Activites

TID PID EIP EAX (Usermode EIP) Filepath Completion Count Source Address Symbol
TID PID Path Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Value Completion Count Source Address Symbol
PID Filepath Base Length Protection Completion Count Source Address Symbol
1764 C:\long sleep 2s.exe 850000 12FF1C page read and write success or wait 1 1400813A HeapCreate
1764 C:\long sleep 2s.exe 850000 12FF20 page read and write success or wait 1 1400813A HeapCreate
1764 C:\long sleep 2s.exe 860000 12FE78 page read and write success or wait 1 140098EB VirtualAlloc
1764 C:\long sleep 2s.exe 860000 12FE68 page read and write success or wait 1 14009977 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:47 0 1 0
09:39:48 0 1 0

System Activites

System info class Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 850000 Length: 12FF1C Allocation Type: unknown Protection: page read and write success or wait 525924732
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 850000 Length: 12FF20 Allocation Type: unknown Protection: page read and write success or wait 525925069
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 860000 Length: 12FE78 Allocation Type: unknown Protection: page read and write success or wait 525929215
Memory allocated PID: 1764 Path: C:\long sleep 2s.exe Base: 860000 Length: 12FE68 Allocation Type: unknown Protection: page read and write success or wait 525929599
Process created PID: 1492 Path: C:\WINDOWS\system32\cmd.exe Cmdline: cmd /c md C:\WINDOWS\system32\LogFiles Createflags: none success or wait 526245228
Process created PID: 1696 Path: C:\WINDOWS\explorer.exe Cmdline: explorer C:\ Createflags: none success or wait 527026603
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 530689848
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 530693545
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531089668
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531098322
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531147099
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531147891
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531196435
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531197320
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531243659
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531244427
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531303527
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531304016
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531357896
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531358690
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531408728
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531413725
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531463745
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531464539
File opened Path: C:\long sleep 2s.exe Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file and open reparse point Attributes: none Content Overwritten: null success or wait 531514287
File created Path: C:\WINDOWS\system32\LogFiles\smss.exe Access: read attributes and delete and synchronize and generic write Options: sequential only and synchronous io non alert and non directory file Attributes: archive Content Overwritten: null success or wait 531514785
File other op Path: C:\WINDOWS\system32\LogFiles\smss.exe New path: Disposition: BasicInformation Data : Creation Time: 01:00 01-01-1601 Last Access Time: 01:00 01-01-1601 Last Write Time: 01:00 01-01-1601 Change Time: 01:00 01-01-1601 File Attributes: readony and system and directory and archive and temporary success or wait 531562763
Process created PID: 260 Path: C:\WINDOWS\system32\cmd.exe Cmdline: cmd /c C:\WINDOWS\system32\LogFiles\smss.exe Createflags: none success or wait 531606008
Process terminated PID: 1764 Path: C:\long sleep 2s.exe success or wait 531704926
General
Start time: 09:39:47
Start date: 24/01/2012
Path: C:\WINDOWS\system32\cmd.exe
Wow64 process (32bit): false
Commandline: cmd /c md C:\WINDOWS\system32\LogFiles
Imagebase: 0x4ad00000
File size: 389120 bytes
MD5 hash: 6D778E0F95447E6546553EEEA709D03C

File Activites

File Path Access Options Content overwritten Completion Count Source Address Symbol
File Path Access Attributes Options Completion Count Source Address Symbol
C:\WINDOWS\system32\LogFiles read data or list directory and synchronize normal directory file and synchronous io non alert and open for backup ident success or wait 1 4AD0B2AC CreateDirectoryW
File Path Disposition Data Ascii Data Completion Count Source Address Symbol

Section Activites

File Path Access Type Base Size Mapped to pid Protection Completion Count
\KnownDlls\kernel32.dll write and read and execute unknown 7C800000 1007616 own pid read write success or wait 1
unknown query and write and read and execute and extend size reserve 7C800000 1007616 own pid read write success or wait 1
\NLS\NlsSectionUnicode read unknown 270000 90112 own pid readonly success or wait 1
\NLS\NlsSectionLocale read unknown 290000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortkey query and read unknown 2E0000 266240 own pid readonly success or wait 1
\NLS\NlsSectionSortTbls read unknown 330000 24576 own pid readonly success or wait 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\NLS\NlsSectionSortkey00000409 read unknown unknown unknown unknown unknown object name not found 1
\KnownDlls\msvcrt.dll write and read and execute unknown 77C10000 360448 own pid read write success or wait 1
\KnownDlls\USER32.dll write and read and execute unknown 7E410000 593920 own pid read write success or wait 1
\KnownDlls\GDI32.dll write and read and execute unknown 77F10000 299008 own pid read write success or wait 1
\KnownDlls\ShimEng.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\shimeng.dll query and write and read and execute image 5CB70000 155648 own pid read write success or wait 1
C:\WINDOWS\AppPatch\sysmain.sdb read commit 340000 1208320 own pid readonly success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll write and read and execute commit 480000 1855488 own pid execute success or wait 1
C:\WINDOWS\AppPatch\acgenral.dll query and write and read and execute image 6F880000 1875968 own pid read write success or wait 1
\KnownDlls\ADVAPI32.dll write and read and execute unknown 77DD0000 634880 own pid read write success or wait 1
\KnownDlls\RPCRT4.dll write and read and execute unknown 77E70000 602112 own pid read write success or wait 1
\KnownDlls\Secur32.dll write and read and execute unknown 77FE0000 69632 own pid read write success or wait 1
\KnownDlls\WINMM.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\winmm.dll query and write and read and execute image 76B40000 184320 own pid read write success or wait 1
\KnownDlls\ole32.dll write and read and execute unknown 774E0000 1302528 own pid read write success or wait 1
\KnownDlls\OLEAUT32.dll write and read and execute unknown 77120000 569344 own pid read write success or wait 1
\KnownDlls\MSACM32.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\msacm32.dll query and write and read and execute image 77BE0000 86016 own pid read write success or wait 1
\KnownDlls\VERSION.dll write and read and execute unknown 77C00000 32768 own pid read write success or wait 1
\KnownDlls\SHELL32.dll write and read and execute unknown 7C9C0000 8482816 own pid read write success or wait 1
\KnownDlls\SHLWAPI.dll write and read and execute unknown 77F60000 483328 own pid read write success or wait 1
\KnownDlls\USERENV.dll write and read and execute unknown 769C0000 737280 own pid read write success or wait 1
\KnownDlls\UxTheme.dll write and read and execute unknown unknown unknown unknown unknown object name not found 1
C:\WINDOWS\system32\uxtheme.dll query and write and read and execute image 5AD70000 229376 own pid read write success or wait 1
\NLS\NlsSectionCType read unknown 490000 12288 own pid readonly success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll write and read and execute commit 410000 110592 own pid execute success or wait 1
C:\WINDOWS\system32\imm32.dll query and write and read and execute image 76390000 118784 own pid read write success or wait 1
C:\WINDOWS\system32\shell32.dll read commit 970000 8462336 own pid readonly success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll write and read and execute commit 970000 1056768 own pid execute success or wait 1
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll query and write and read and execute image 773D0000 1060864 own pid read write success or wait 1
C:\WINDOWS\WindowsShell.Manifest write and read and execute commit 440000 4096 own pid execute success or wait 1
C:\WINDOWS\WindowsShell.Manifest query and read commit 440000 4096 own pid readonly success or wait 1
C:\WINDOWS\WindowsShell.Manifest read commit 440000 4096 own pid readonly success or wait 1
\KnownDlls\comctl32.dll write and read and execute unknown 5D090000 630784 own pid read write success or wait 1
C:\WINDOWS\system32\comctl32.dll read commit 970000 618496 own pid readonly success or wait 1

Registry Activites

Key Path Name Completion Count Source Address Symbol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor PathCompletionChar success or wait 1 4AD04B37 RegQueryValueExW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor AutoRun success or wait 1 4AD04BB8 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DisableUNCCheck object name not found 1 4AD04A2A RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor EnableExtensions success or wait 1 4AD04A4F RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DelayedExpansion object name not found 1 4AD04A88 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor DefaultColor success or wait 1 4AD04AAD RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor CompletionChar success or wait 1 4AD04AE5 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor PathCompletionChar object name not found 1 4AD04B37 RegQueryValueExW
HKEY_USERS\Software\Microsoft\Command Processor AutoRun object name not found 1 4AD04BB8 RegQueryValueExW

Mutex Activites

Name Completion Count Source Address Symbol

Process Activites

PID Process info class Completion Count Source Address Symbol
PID Filepath Completion Count Source Address Symbol

Memory Activites

PID Filepath Base Length Protection Completion Count Source Address Symbol
1492 C:\WINDOWS\system32\cmd.exe 970000 13FE10 page read and write success or wait 1 4AD04578 VirtualAlloc
PID Filepath Base Length New Protection Old Protection Completion Count Source Address Symbol
Time Private Usage (mb) Workingset (mb) Page File Usage (mb)
09:39:47 1 0 1

System Activites

System info class Completion Count Source Address Symbol
Chronological Activities
Operation Data Completion Time