anubis left
Anubis - Analysis Report
anubis right

Analysis Report for installer_70100.exe

Comment on this report

Summary:

Description Risk
Changes security settings of Internet Explorer: This system alteration could seriously affect safety surfing the World Wide Web. medium
Creates files in the Windows system directory: Malware often keeps copies of itself in the Windows directory to stay undetected by users. medium
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Spawns Processes: The executable produces processes during the execution. low
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 241 s 
Report created: 04/18/09, 07:07:00 UTC 
Termination reason: Timeout 
Program version: 1.67.0 

1.a) - Network Activity

  -  Unknown UDP Traffic:  
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 99 - Transferred inbound Bytes: 661
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 324 - Transferred inbound Bytes: 1140

  -  TCP Connection Attempts:  
from ANUBIS:1041 to 94.247.2.215:80
from ANUBIS:1043 to 94.247.2.215:80
from ANUBIS:1044 to 94.247.2.215:80
from ANUBIS:1045 to 94.247.2.215:80
from ANUBIS:1046 to 94.247.2.215:80
from ANUBIS:1047 to 94.247.2.215:80
from ANUBIS:1048 to 94.247.2.215:80
from ANUBIS:1049 to 74.125.43.99:80
from ANUBIS:1050 to 94.247.2.215:80
from ANUBIS:1051 to 94.247.2.215:80
from ANUBIS:1052 to 94.247.2.215:80
from ANUBIS:1053 to 94.247.2.215:80
from ANUBIS:1054 to 94.247.2.215:80
from ANUBIS:1055 to 94.247.2.215:80
from ANUBIS:1056 to 94.247.2.215:80
from ANUBIS:1057 to 94.247.2.215:80
from ANUBIS:1042 to 94.247.2.215:80

2. sample.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: sample.exe 
MD5: faf7bf2d9cd6d578b774d9154703cfaf 
SHA-1: 96e8a8e82d1a714f9a5b8f99b1b481a727f37a4e 
File Size: 666624 Bytes
Command Line: "C:\sample.exe" 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​Normaliz.dll  0x003E0000  0x00009000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​wininet.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​urlmon.dll  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​ieframe.dll  0x42EF0000  0x005CD000 
C:\​WINDOWS\​system32\​uxtheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​NETAPI32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​System32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​sensapi.dll  0x722B0000  0x00005000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​system32\​LINKINFO.dll  0x76980000  0x00008000 
C:\​WINDOWS\​system32\​ntshrui.dll  0x76990000  0x00025000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​ATL.DLL  0x76B20000  0x00011000 
C:\​WINDOWS\​system32\​WINMM.dll  0x76B40000  0x0002D000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​WINDOWS\​system32\​iphlpapi.dll  0x76D60000  0x00019000 
C:\​WINDOWS\​system32\​rtutils.dll  0x76E80000  0x0000E000 
C:\​WINDOWS\​system32\​rasman.dll  0x76E90000  0x00012000 
C:\​WINDOWS\​system32\​TAPI32.dll  0x76EB0000  0x0002F000 
C:\​WINDOWS\​system32\​RASAPI32.dll  0x76EE0000  0x0003C000 
C:\​WINDOWS\​system32\​DNSAPI.dll  0x76F20000  0x00027000 
C:\​WINDOWS\​system32\​rasadhlp.dll  0x76FC0000  0x00006000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​system32\​oleaut32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​SETUPAPI.dll  0x77920000  0x000F3000 
C:\​WINDOWS\​system32\​Apphelp.dll  0x77B40000  0x00022000 
C:\​WINDOWS\​system32\​version.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​msv1_0.dll  0x77C70000  0x00024000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​shell32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​user32.dll  0x7E410000  0x00091000 

  - Ikarus Virus Scanner  
Trojan.Crypt (Sig-Id:27776681)

  - Popups  
Window Name Window Text Screenshot Number of Displayed Times
Antivirus Plus Setup  Scan computer after the installation process ends. < Back Cancel Next >   screenshot

2.a) sample.exe - Registry Activities

  - Registry Values Modified:  
Key Name New Value
HKLM\​SYSTEM\​CURRENTCONTROLSET\​HARDWARE PROFILES\​CURRENT\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info ProxyEnable 
HKLM\​SYSTEM\​ControlSet001\​Services\​SharedAccess\​Parameters\​FirewallPolicy\​StandardProfile\​AuthorizedApplications\​List  C:\​WINDOWS\​system\​kernel32.exe  C:\​WINDOWS\​system\​kernel32.exe:*:Enabled:kernel32 
HKLM\​SYSTEM\​ControlSet001\​Services\​SharedAccess\​Parameters\​FirewallPolicy\​StandardProfile\​AuthorizedApplications\​List  C:\​sample.exe  C:\​sample.exe:*:Enabled:installer 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common AppData  C:\​Documents and Settings\​All Users\​Application Data 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common Desktop  C:\​Documents and Settings\​All Users\​Desktop 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common Documents  C:\​Documents and Settings\​All Users\​Documents 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common Programs  C:\​Documents and Settings\​All Users\​Start Menu\​Programs 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common Start Menu  C:\​Documents and Settings\​All Users\​Start Menu 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  CommonMusic  C:\​Documents and Settings\​All Users\​Documents\​My Music 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  CommonPictures  C:\​Documents and Settings\​All Users\​Documents\​My Pictures 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  CommonVideo  C:\​Documents and Settings\​All Users\​Documents\​My Videos 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​{d14d83ce-7d74-11dc-97e2-806d6172696f}\​  BaseClass  Drive 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​{d14d83cf-7d74-11dc-97e2-806d6172696f}\​  BaseClass  Drive 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  AppData  C:\​Documents and Settings\​user\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cookies  C:\​Documents and Settings\​user\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Desktop  C:\​Documents and Settings\​user\​Desktop 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  History  C:\​Documents and Settings\​user\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  My Pictures  C:\​Documents and Settings\​user\​My Documents\​My Pictures 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Personal  C:\​Documents and Settings\​user\​My Documents 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Start Menu  C:\​Documents and Settings\​user\​Start Menu 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info IntranetName 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info ProxyBypass 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info UNCAsIntranet 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​ShellNoRoam\​MUICache\​  C:\​WINDOWS\​system\​kernel32.exe   kernel32.exe  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info MigrateProxy 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info ProxyEnable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  info SavedLegacySettings  0x460000006800000001000000000000000000000000000000040000000000 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​CLASSES\​.EXE    exefile 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{00021401-0000-0000-C000-000000000046}\​INPROCSERVER32    shell32.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{00021401-0000-0000-C000-000000000046}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{20D04FE0-3AEA-1069-A2D8-08002B30309D}\​INPROCSERVER32    %SystemRoot%\​system32\​SHELL32.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{59031A47-3F72-44A7-89C5-5595FE6B30EE}\​INPROCSERVER32    %SystemRoot%\​system32\​SHELL32.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\​INPROCSERVER32    C:\​WINDOWS\​system32\​urlmon.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\​INPROCSERVER32  ThreadingModel  Both 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​SHELLFOLDER  WantsParseDisplayName   
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{AEB6717E-7E19-11D0-97EE-00C04FD91972}\​INPROCSERVER32    shell32.dll 
HKLM\​SOFTWARE\​CLASSES\​DIRECTORY  AlwaysShowExt   
HKLM\​SOFTWARE\​CLASSES\​DRIVE\​SHELLEX\​FOLDEREXTENSIONS\​{FBEB8A05-BEEE-4442-804E-409D6C4515E9}  DriveMask  32 
HKLM\​SOFTWARE\​CLASSES\​EXEFILE\​SHELL\​OPEN\​COMMAND    "%1" %* 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{000214E6-0000-0000-C000-000000000046}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{B722BCCB-4E68-101B-A2BC-00AA00404770}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\​TYPELIB    {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} 
HKLM\​SOFTWARE\​CLASSES\​MIME\​DATABASE\​CONTENT TYPE\​TEXT/HTML  Extension  .htm 
HKLM\​SOFTWARE\​CLASSES\​MIME\​DATABASE\​CONTENT TYPE\​TEXT/PLAIN  Extension  .txt 
HKLM\​SOFTWARE\​CLASSES\​NETWORK\​SHARINGHANDLER    ntshrui.dll 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedHigh  29887276 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedLow  2933474304 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​App Paths\​IEXPLORE.EXE    C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnablePunycode 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  UrlEncoding  0x00000000 
HKLM\​SYSTEM\​CurrentControlSet\​Control\​Session Manager  CriticalSectionTimeout  2592000 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​SYSTEM\​Setup  OsLoaderPath  \​ 
HKLM\​SYSTEM\​Setup  SystemPartition  \​Device\​HarddiskVolume1 
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​SYSTEM\​WPA\​MediaCenter  Installed 
HKLM\​Software\​Classes\​CLSID\​{871c5380-42a0-1069-a2ea-08002b30309d}\​InProcServer32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​Software\​Microsoft\​COM3  Com+Enabled 
HKLM\​Software\​Microsoft\​COM3  REGDBVersion  0x0f00000000000000  14 
HKLM\​Software\​Microsoft\​CTF\​SystemShared  CUAS 
HKLM\​Software\​Microsoft\​Internet Explorer\​Main\​FeatureControl\​FEATURE_BEHAVIORS 
HKLM\​Software\​Microsoft\​Internet Explorer\​Main\​FeatureControl\​FEATURE_DISABLE_MK_PROTOCOL 
HKLM\​Software\​Microsoft\​Rpc\​SecurityService  10  secur32.dll 
HKLM\​Software\​Microsoft\​Tracing  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  ConsoleTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableFileTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileDirectory  %windir%\​tracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  MaxFileSize  1048576 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​IMM  Ime File  msctfime.ime 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  AllUsersProfile  All Users 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  DefaultUserProfile  Default User 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  ProfilesDirectory  %SystemDrive%\​Documents and Settings  15 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  CentralProfile   
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  Flags 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  ProfileImagePath  %SystemDrive%\​Documents and Settings\​user 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  ProfileLoadTimeHigh  29931941 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  ProfileLoadTimeLow  1446385964 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  State  256 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  CommonFilesDir  C:\​Program Files\​Common Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  DevicePath  %SystemRoot%\​inf 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  ProgramFilesDir  C:\​Program Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​FileAssociation  CutList  0x4100700070006c00690063006100740069006f006e002000460069006c00 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​ShellExecuteHooks  {AEB6717E-7E19-11d0-97EE-00C04FD91972}   
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common AppData  %ALLUSERSPROFILE%\​Application Data 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common Desktop  %ALLUSERSPROFILE%\​Desktop 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common Documents  %ALLUSERSPROFILE%\​Documents 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common Programs  %ALLUSERSPROFILE%\​Start Menu\​Programs 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common Start Menu  %ALLUSERSPROFILE%\​Start Menu 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com     
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com\​related  http 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  DriverCachePath  %SystemRoot%\​Driver Cache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  LogLevel 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackCachePath  c:\​windows\​ServicePackFiles\​ServicePackCache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackSourcePath  c:\​windows\​ServicePackFiles 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  SourcePath  D:\​ 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  AuthenticodeEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  DefaultLevel  262144 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  ExecutableTypes  0x410044004500000041004400500000004200410053000000420041005400 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  PolicyScope 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemData  0x5eab304f957a49896a006c1c31154015 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemSize  779 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemData  0x67b0d48b343a3fd3bce9dc646704f394 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemSize  517 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemData  0x327802dcfef8c893dc8ab006dd847d1d 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemSize  918 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemData  0xbd9a2adb42ebd8560e250e4df8162f67 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemSize  229 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemData  0x386b085f84ecf669d36b956a22c01e80 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemSize  370 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  ItemData  %HKEY_CURRENT_USER\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders\​Cache%OLK* 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  SaferFlags 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER  12 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Capabilities  16464 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Comment  Digest SSPI Authentication Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Name  Digest 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  RpcId  65535 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  TokenSize  65535 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Capabilities  55 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Comment  DPA Security Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Name  DPA 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  RpcId  17 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  TokenSize  768 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Capabilities  55 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Comment  MSN Security Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Name  MSN 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  RpcId  18 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  TokenSize  768 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​MediaProperties\​PrivateProperties\​Joystick\​Winmm  wheel 
HKLM\​System\​CurrentControlSet\​Control\​ProductOptions  ProductType  WinNT 
HKLM\​System\​CurrentControlSet\​Control\​SecurityProviders  SecurityProviders  msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll 
HKLM\​System\​CurrentControlSet\​Control\​SecurityProviders\​SaslProfiles  GSSAPI  Kerberos 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  ComSpec  %SystemRoot%\​system32\​cmd.exe  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  FP_NO_HOST_CHECK  NO  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  NUMBER_OF_PROCESSORS  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  OS  Windows_NT  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PATHEXT  .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_ARCHITECTURE  x86  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_IDENTIFIER  x86 Family 6 Model 3 Stepping 3, GenuineIntel  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_LEVEL  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_REVISION  0303  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  Path  %SystemRoot%\​system32;%SystemRoot%;%SystemRoot%\​System32\​Wbem  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TEMP  %SystemRoot%\​TEMP  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TMP  %SystemRoot%\​TEMP  12 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  windir  %SystemRoot%  12 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  UseDomainNameDevolution 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Num_Catalog_Entries 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  DisplayString  Tcpip 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  ProviderId  0x409d05229e7ecf11ae5a00aa00a7112b 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  SupportedNameSpace  12 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  DisplayString  NTDS 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  LibraryPath  %SystemRoot%\​System32\​winrnr.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  ProviderId  0xee37263b80e5cf11a55500c04fd8d4ac 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  SupportedNameSpace  32 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  DisplayString  Network Location Awareness (NLA) Namespace 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  ProviderId  0x3a244266a83ba64abaa52e0bd71fdd83 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  SupportedNameSpace  15 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Next_Catalog_Entry_ID  1012 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Num_Catalog_Entries  11 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000001  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000002  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000003  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000004  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000005  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000006  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000007  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000008  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000009  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000010  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000011  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​Setup  SystemSetupInProgress 
HKLM\​System\​WPA\​PnP  seed  1374283966 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TEMP  %USERPROFILE%\​Local Settings\​Temp  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TMP  %USERPROFILE%\​Local Settings\​Temp  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  CertificateRevocation 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  DisableCachingOfSSLPages 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableHttp1_1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableNegotiate 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  MimeExclusionListForCache  multipart/mixed multipart/x-mixed-replace multipart/x-byteranges  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  PrivacyAdvanced 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  SecureProtocols  160 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnPost  0x01000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnZoneCrossing 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Winlogon  ParseAutoexec 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​  ShellState  0x2400000033880000000000000000000000000000010000000d0000000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  DontPrettyPath 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  Filter 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  Hidden 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  HideFileExt 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  HideIcons 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  MapNetDrvBtn 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  NoNetCrawling 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  SeparateProcess 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  ShowCompColor 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  ShowInfoTip 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  ShowSuperHidden 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Advanced  WebView 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​CPC\​Volume\​{d14d83ce-7d74-11dc-97e2-806d6172696f}\​  Data  0x000000005c005c003f005c0049004400450023004300640052006f006d00 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​CPC\​Volume\​{d14d83ce-7d74-11dc-97e2-806d6172696f}\​  Generation 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​CPC\​Volume\​{d14d83cf-7d74-11dc-97e2-806d6172696f}\​  Data  0x000000005c005c003f005c00530054004f00520041004700450023005600 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​CPC\​Volume\​{d14d83cf-7d74-11dc-97e2-806d6172696f}\​  Generation  20 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  AppData  %USERPROFILE%\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cache  %USERPROFILE%\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cookies  %USERPROFILE%\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Desktop  %USERPROFILE%\​Desktop 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  History  %USERPROFILE%\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Local Settings  %USERPROFILE%\​Local Settings 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  My Pictures  %USERPROFILE%\​My Documents\​My Pictures 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Personal  %USERPROFILE%\​My Documents 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Start Menu  %USERPROFILE%\​Start Menu 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache  Signature  Client UrlCache MMF Ver 5.2 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CacheLimit  163410 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CachePrefix   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CachePrefix  Cookie: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheOptions  11 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePath  %USERPROFILE%\​Local Settings\​History\​History.IE5\​MSHist012008051620080517 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePrefix  :2008051620080517:  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheLimit  1000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePath  %USERPROFILE%\​UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePrefix  UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePath  %USERPROFILE%\​Local Settings\​Application Data\​Microsoft\​Feeds Cache 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePrefix  feedplat: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CachePrefix  Visited: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​     
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  @ivt 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  file 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  ftp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  http 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  https 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  shell 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​0  1806 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​0  Flags  33 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​1  Flags  475 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​2  Flags  71 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  1A10 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  {AEBA21FA-782A-4A90-978D-B72164C80120}  0x1a3761592352350c7a5f20172f1e1a190e2b01731e281a041b0c3bc22127 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​4  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Shell Extensions\​Cached  {871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0x401  0x01000000310032003a893fef1312c801 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​ShellNoRoam\​MUICache  LangID  0x0904 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  MigrateProxy 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  ProxyEnable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  DefaultConnectionSettings  0x3c0000000200000001000000000000000000000000000000040000000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  SavedLegacySettings  0x460000006700000001000000000000000000000000000000040000000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  APPDATA  C:\​Documents and Settings\​user\​Application Data  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  CLIENTNAME    12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEDRIVE  C:  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEPATH  \​Documents and Settings\​user  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMESHARE    12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  LOGONSERVER  \​\​USER  12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  SESSIONNAME  Console  12 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​Software\​Classes  Key Change,Value Change 
HKLM\​Software\​Classes\​CLSID  Key Change,Value Change 
HKLM\​Software\​Microsoft\​COM3  Key Change,Value Change 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  Attributes Change,Value Change,Security Descriptor Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Key Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Key Change 
HKU  Key Change,Value Change 

2.b) sample.exe - File Activities

  - Files Deleted:  
C:\Documents and Settings\user\Cookies\user@google[2].txt
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\google_com[1].htm
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\real[1].htm

  - Files Created:  
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\Antivirus Plus.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\EULA.lnk
C:\Documents and Settings\user\Cookies\user@google[3].txt
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\AntivirusPlus[1].exe
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\dmns[1].cfg
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\google_com[1].htm
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\real[1].htm
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\BNPHK11H\InternetExplorer[1].dll
C:\Program Files\Antivirus Plus\
C:\Program Files\Antivirus Plus\AntivirusPlus.exe
C:\WINDOWS\system32\InternetExplorer.dll
C:\WINDOWS\system32\dmns.cfg
C:\WINDOWS\system\kernel32.exe

  - Files Read:  
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini
C:\Documents and Settings\All Users\Documents\My Videos\desktop.ini
C:\Documents and Settings\All Users\Documents\desktop.ini
C:\Documents and Settings\All Users\Start Menu\desktop.ini
C:\Documents and Settings\user\Application Data\desktop.ini
C:\Documents and Settings\user\Cookies\user@google[2].txt
C:\Documents and Settings\user\My Documents\My Pictures\desktop.ini
C:\Documents and Settings\user\My Documents\desktop.ini
C:\Documents and Settings\user\Start Menu\desktop.ini
C:\Program Files\Antivirus Plus\AntivirusPlus.exe
C:\WINDOWS\Registration\R00000000000f.clb
C:\WINDOWS\system\kernel32.exe
PIPE\ROUTER
PIPE\lsarpc
PIPE\srvsvc
PIPE\wkssvc
c:\autoexec.bat

  - Files Modified:  
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\Antivirus Plus.lnkinfo
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\EULA.lnkinfo
C:\Documents and Settings\user\Cookies\user@google[3].txtinfo
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\AntivirusPlus[1].exeinfo
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5E7EYQDH\dmns[1].cfginfo
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\BNPHK11H\InternetExplorer[1].dllinfo
C:\Program Files\Antivirus Plus\AntivirusPlus.exeinfo
C:\WINDOWS\system32\InternetExplorer.dllinfo
C:\WINDOWS\system32\dmns.cfginfo
C:\WINDOWS\system\kernel32.exeinfo
Ipinfo
MountPointManagerinfo
PIPE\ROUTERinfo
PIPE\lsarpcinfo
PIPE\srvsvcinfo
PIPE\wkssvcinfo
WMIDataDeviceinfo
\Device\Afd\AsyncConnectHlpinfo
\Device\Afd\Endpointinfo
\Device\Ipinfo
\Device\RasAcdinfo
\Device\Tcpinfo

  - Directories Created:  
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\
C:\Program Files\Antivirus Plus\

  - File System Control Communication:  
File Control Code Times
C:\exec  0x00090028 
PIPE\lsarpc  0x0011C017  66 
PIPE\wkssvc  0x0011C017 
PIPE\ROUTER  0x0011C017 
PIPE\srvsvc  0x0011C017 
C:\Program Files\Antivirus Plus\AntivirusPlus.exe  0x000900C0 

  - Device Control Communication:  
File Control Code Times
\Device\KsecDD  0x00390008 
WMIDataDevice  0x0022414C 
WMIDataDevice  0x00228144 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047)  28 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_GET_SOCK_NAME (0x0001202F) 
\Device\Afd\Endpoint  AFD_SET_INFO (0x0001203B)  24 
\Device\Afd\AsyncConnectHlp  AFD_CONNECT (0x00012007) 
\Device\Afd\Endpoint  AFD_SELECT (0x00012024) 
unnamed file  0x00120028 
\Device\Afd\Endpoint  AFD_SEND (0x0001201F) 
\Device\Afd\Endpoint  AFD_RECV (0x00012017)  2147 
IDE#CdRomQEMU_QEMU_CD-ROM________________________0.9.____#4d51303030302033202020202020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}  0x004D0008 
MountPointManager  0x006D0008 
STORAGE#Volume#1&30a96598&0&Signature95619561Offset7E00Length13F291800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}  0x004D0008 
MountPointManager  0x006D0034 
\Device\Tcp  0x00120003 
\Device\Afd\Endpoint  AFD_DISCONNECT (0x0001202B) 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\System32\mswsock.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
C:\WINDOWS\WindowsShell.Manifest
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\Apphelp.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\IMM32.DLL
C:\WINDOWS\system32\LINKINFO.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\Msimtf.dll
C:\WINDOWS\system32\PSAPI.DLL
C:\WINDOWS\system32\RASAPI32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\ieframe.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\msctfime.ime
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\ntshrui.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\rpcss.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\sensapi.dll
C:\WINDOWS\system32\shell32.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\ws2_32.dll
C:\WINDOWS\system\kernel32.exe
C:\Windows\AppPatch\sysmain.sdb

2.c) sample.exe - Windows Service Activities

  - Services Started:  
RASMAN

2.d) sample.exe - Process Activities

  - Processes Created:  
Executable Command Line
C:\WINDOWS\system\kernel32.exe   
C:\WINDOWS\system\kernel32.exe   "C:\WINDOWS\system\kernel32.exe "  

  - Remote Threads Created:  
Affected Process
C:\WINDOWS\system\kernel32.exe

  - Thread Overview:  
Time Number of threads
After 18 seconds
After 224 seconds

  - Foreign Memory Regions Read:  
Process: C:\WINDOWS\system\kernel32.exe

  - Foreign Memory Regions Written:  
Process: C:\WINDOWS\system\kernel32.exe

2.e) sample.exe - Network Activity

  - DNS Queries:  
Name Query Type Query Result Successful Protocol
addedantiviruspro.com  DNS_TYPE_A  94.247.2.215   
google.com  DNS_TYPE_A  74.125.45.100   
www.google.com  DNS_TYPE_A     

  -  HTTP Conversations:  
From ANUBIS:1032 to 94.247.2.215:80 - [addedantiviruspro.com]
Request: GET /cb/real.php?id=
Response: 200 "OK"
Request: GET /install/AntivirusPlus.exe
Response: 200 "OK"
Request: GET /cfg/dmns.cfg
Response: 200 "OK"
Request: GET /install/InternetExplorer.dll
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /install/AntivirusPlus.grn
Response: 200 "OK"
Request: GET /redirect.php
Response: 302 "Found"
Request: GET /se.exe
Response: 200 "OK"
From ANUBIS:1033 to 74.125.45.100:80 - [google.com]
Request: GET /
Response: 301 "Moved Permanently"
Request: GET /
Response: 301 "Moved Permanently"
From ANUBIS:1034 to 74.125.43.99:80 - [www.google.com]
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"
Request: GET /
Response: 200 "OK"

3. services.exe

  - General information about this executable  
Analysis Reason: NtConnectPort(\RPC Control\ntsvcs was called. 
Filename: services.exe 
MD5: 0e776ed5f7cc9f94299e70461b7b8185 
SHA-1: cb5a33cec4c7b8ef4bd5dc8c241005b66b26cbbf 
File Size: 108544 Bytes
Command Line: C:\WINDOWS\system32\services.exe 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​NCObjAPI.DLL  0x5F770000  0x0000C000 
C:\​WINDOWS\​system32\​MSVCP60.dll  0x76080000  0x00065000 
C:\​WINDOWS\​system32\​SCESRV.dll  0x7DBD0000  0x00051000 
C:\​WINDOWS\​system32\​AUTHZ.dll  0x776C0000  0x00012000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​umpnpmgr.dll  0x7DBA0000  0x00021000 
C:\​WINDOWS\​system32\​WINSTA.dll  0x76360000  0x00010000 
C:\​WINDOWS\​system32\​NETAPI32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​ShimEng.dll  0x5CB70000  0x00026000 
C:\​WINDOWS\​AppPatch\​AcAdProc.dll  0x47260000  0x0000F000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​system32\​Apphelp.dll  0x77B40000  0x00022000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​eventlog.dll  0x77B70000  0x00011000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​WINDOWS\​system32\​WS2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​wtsapi32.dll  0x76F50000  0x00008000 

3.a) services.exe - Registry Activities

  - Registry Keys Created:  
HKLM\​System\​CurrentControlSet\​Enum\​Root\​LEGACY_TAPISRV\​0000\​Control
HKLM\​System\​CurrentControlSet\​Enum\​Root\​LEGACY_RASMAN\​0000\​Control

  - Registry Values Modified:  
Key Name New Value
HKLM\​System\​CurrentControlSet\​Enum\​Root\​LEGACY_RASMAN\​0000\​Control  ActiveService  RasMan 
HKLM\​System\​CurrentControlSet\​Enum\​Root\​LEGACY_TAPISRV\​0000\​Control  ActiveService  TapiSrv 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0303\​4&2C5A7332&0  ClassGUID  {4D36E96B-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0400\​4&2C5A7332&0  ClassGUID  {4D36E978-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0501\​1  ClassGUID  {4D36E978-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0700\​4&2C5A7332&0  ClassGUID  {4D36E969-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0A03\​1  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI\​PNP0F13\​4&2C5A7332&0  ClassGUID  {4D36E96F-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ACPI_HAL\​PNP0C08\​0  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​DISPLAY\​DEFAULT_MONITOR\​4&2946A9FF&0&11223344&00&02  ClassGUID  {4D36E96E-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​IDE\​CDROMQEMU_QEMU_CD-ROM________________________0.9.____\​4D51303030302033202020202020202020202020  ClassGUID  {4D36E965-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​IDE\​DISKQEMU_HARDDISK___________________________0.9.1___\​4D51303030302031202020202020202020202020  ClassGUID  {4D36E967-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ISAPNP\​READDATAPORT\​0  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​LPTENUM\​MICROSOFTRAWPORT\​5&34A37E9F&0&LPT1  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCIIDE\​IDECHANNEL\​4&3DE75EA&0&0  ClassGUID  {4D36E96A-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCIIDE\​IDECHANNEL\​4&3DE75EA&0&1  ClassGUID  {4D36E96A-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_1013&DEV_00B8&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&10  ClassGUID  {4D36E968-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_10EC&DEV_8029&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&18  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_10EC&DEV_8029&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&18  DeviceDesc  Realtek RTL8029(AS)-based Ethernet Adapter (Generic) 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_10EC&DEV_8029&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&18  Driver  {4D36E972-E325-11CE-BFC1-08002BE10318}\​0001 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_8086&DEV_1237&SUBSYS_00000000&REV_02\​3&13C0B0C5&0&00  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_8086&DEV_7000&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&08  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​PCI\​VEN_8086&DEV_7010&SUBSYS_00000000&REV_00\​3&13C0B0C5&0&09  ClassGUID  {4D36E96A-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​ACPI_HAL\​0000  ClassGUID  {4D36E966-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​DMIO\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​FTDISK\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_AFD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_BEEP\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_DMBOOT\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_DMLOAD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_FIPS\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_GPC\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_HTTP\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_IPNAT\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_IPSEC\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_KSECDD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_MNMDD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_MOUNTMGR\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NDISTAPI\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NDISUIO\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NDIS\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NDPROXY\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NETBT\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_NULL\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_PARTMGR\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_PARVDM\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_RASACD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_RDPCDD\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_TCPIP\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_VGASAVE\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_VOLSNAP\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​LEGACY_WANARP\​0000  ClassGUID  {8ECC055D-047F-11D1-A537-0000F8753ED1} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MEDIA\​MS_MMACM  ClassGUID  {4D36E96C-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MEDIA\​MS_MMDRV  ClassGUID  {4D36E96C-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MEDIA\​MS_MMMCI  ClassGUID  {4D36E96C-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MEDIA\​MS_MMVCD  ClassGUID  {4D36E96C-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MEDIA\​MS_MMVID  ClassGUID  {4D36E96C-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_L2TPMINIPORT\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_NDISWANIP\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_NDISWANIP\​0000  DeviceDesc  WAN Miniport (IP) 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_NDISWANIP\​0000  Driver  {4D36E972-E325-11CE-BFC1-08002BE10318}\​0008 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_PPPOEMINIPORT\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_PPTPMINIPORT\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_PSCHEDMP\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_PSCHEDMP\​0001  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​MS_PTIMINIPORT\​0000  ClassGUID  {4D36E972-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​RDPDR\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​RDP_KBD\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​RDP_MOU\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​SYSTEM\​0000  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​SYSTEM\​0001  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​ROOT\​SYSTEM\​0002  ClassGUID  {4D36E97D-E325-11CE-BFC1-08002BE10318} 
HKLM\​SYSTEM\​CONTROLSET001\​ENUM\​STORAGE\​VOLUME\​1&30A96598&0&SIGNATURE95619561OFFSET7E00LENGTH13F291800  ClassGUID  {71A27CDD-812A-11D0-BEC7-08002BE2092F} 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​PlugPlay  PlugPlayServiceType 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​RasMan\​Enum  Root\​LEGACY_RASMAN\​0000 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​RasMan\​Enum  Count 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​RpcSs\​Enum  Root\​LEGACY_RPCSS\​0000 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​RpcSs\​Enum  Count 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​TapiSrv\​Enum  Root\​LEGACY_TAPISRV\​0000 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​TapiSrv\​Enum  Count 
HKLM\​System\​CurrentControlSet\​Services\​PlugPlay  ObjectName  LocalSystem 
HKLM\​System\​CurrentControlSet\​Services\​RasMan  ImagePath  %SystemRoot%\​system32\​svchost.exe -k netsvcs 
HKLM\​System\​CurrentControlSet\​Services\​RasMan  ObjectName  LocalSystem 
HKLM\​System\​CurrentControlSet\​Services\​RpcSs  ObjectName  NT Authority\​NetworkService 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  DependOnGroup  0x0000 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  DependOnService  0x4e00650074006d0061006e000000570069006e004d0067006d0074000000 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  DisplayName  Windows Firewall/Internet Connection Sharing (ICS) 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  ErrorControl 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  ImagePath  %SystemRoot%\​system32\​svchost.exe -k netsvcs 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  ObjectName  LocalSystem 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  Start 
HKLM\​System\​CurrentControlSet\​Services\​SharedAccess  Type  32 
HKLM\​System\​CurrentControlSet\​Services\​TapiSrv  ImagePath  %SystemRoot%\​System32\​svchost.exe -k netsvcs 
HKLM\​System\​CurrentControlSet\​Services\​TapiSrv  ObjectName  LocalSystem 

3.b) services.exe - File Activities

  - Files Read:  
C:\ntsvcs, Flags: Named pipe

  - Files Modified:  
C:\PIPE_EVENTROOT\CIMV2SCM EVENT PROVIDER, Flags: Named pipeinfo
C:\WINDOWS\system32\config\SysEvent.Evtinfo
C:\ntsvcs, Flags: Named pipeinfo

  - File System Control Communication:  
File Control Code Times
C:\net\NtControlPipe4, Flags: Named pipe  0x0011C017 
C:\ntsvcs, Flags: Named pipe  0x0011001C 

4. kernel32.exe

  - General information about this executable  
Analysis Reason: Started by sample.exe 
Filename: kernel32.exe 
MD5: 67995bd8253bafde094739f34d8eefda 
SHA-1: 268c688ccdf2d3478e136e9a20d6b08636f03324 
File Size: 1435648 Bytes
Command Line: "C:\WINDOWS\system\kernel32.exe "  
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​Normaliz.dll  0x003E0000  0x00009000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​wininet.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​urlmon.dll  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​uxtheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​NETAPI32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​olepro32.dll  0x5EDD0000  0x00017000 
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​System32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​sensapi.dll  0x722B0000  0x00005000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​WINMM.dll  0x76B40000  0x0002D000 
C:\​WINDOWS\​system32\​iphlpapi.dll  0x76D60000  0x00019000 
C:\​WINDOWS\​system32\​rtutils.dll  0x76E80000  0x0000E000 
C:\​WINDOWS\​system32\​rasman.dll  0x76E90000  0x00012000 
C:\​WINDOWS\​system32\​TAPI32.dll  0x76EB0000  0x0002F000 
C:\​WINDOWS\​system32\​RASAPI32.dll  0x76EE0000  0x0003C000 
C:\​WINDOWS\​system32\​DNSAPI.dll  0x76F20000  0x00027000 
C:\​WINDOWS\​system32\​rasadhlp.dll  0x76FC0000  0x00006000 
C:\​WINDOWS\​system32\​oleaut32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​version.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​msv1_0.dll  0x77C70000  0x00024000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​shell32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​user32.dll  0x7E410000  0x00091000 

  - Ikarus Virus Scanner  
Trojan.Crypt (Sig-Id:27783013)

4.a) kernel32.exe - Registry Activities

  - Registry Values Modified:  
Key Name New Value
HKLM\​SYSTEM\​CURRENTCONTROLSET\​HARDWARE PROFILES\​CURRENT\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info ProxyEnable 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common AppData  C:\​Documents and Settings\​All Users\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  AppData  C:\​Documents and Settings\​user\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cookies  C:\​Documents and Settings\​user\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  History  C:\​Documents and Settings\​user\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info IntranetName 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info ProxyBypass 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info UNCAsIntranet 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info MigrateProxy 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  info ProxyEnable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  info SavedLegacySettings  0x460000006900000001000000000000000000000000000000040000000000 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​CLASSES\​MIME\​DATABASE\​CONTENT TYPE\​TEXT/HTML  Extension  .htm 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnablePunycode 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  UrlEncoding  0x00000000 
HKLM\​SYSTEM\​CurrentControlSet\​Control\​Session Manager  CriticalSectionTimeout  2592000 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​Software\​Microsoft\​CTF\​SystemShared  CUAS 
HKLM\​Software\​Microsoft\​Internet Explorer\​Main\​FeatureControl\​FEATURE_BEHAVIORS 
HKLM\​Software\​Microsoft\​Internet Explorer\​Main\​FeatureControl\​FEATURE_DISABLE_MK_PROTOCOL 
HKLM\​Software\​Microsoft\​Rpc\​SecurityService  10  secur32.dll 
HKLM\​Software\​Microsoft\​Tracing  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  ConsoleTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableFileTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileDirectory  %windir%\​tracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  MaxFileSize  1048576 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​IMM  Ime File  msctfime.ime 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  AllUsersProfile  All Users 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  DefaultUserProfile  Default User 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  ProfilesDirectory  %SystemDrive%\​Documents and Settings 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  ProfileImagePath  %SystemDrive%\​Documents and Settings\​user 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  CommonFilesDir  C:\​Program Files\​Common Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  ProgramFilesDir  C:\​Program Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common AppData  %ALLUSERSPROFILE%\​Application Data 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com     
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com\​related  http 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Capabilities  16464 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Comment  Digest SSPI Authentication Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Name  Digest 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  RpcId  65535 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  TokenSize  65535 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​digest.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Capabilities  55 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Comment  DPA Security Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Name  DPA 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  RpcId  17 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  TokenSize  768 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msapsspc.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Capabilities  55 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Comment  MSN Security Package 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Name  MSN 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  RpcId  18 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  TokenSize  768 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Type  49 
HKLM\​System\​CurrentControlSet\​Control\​Lsa\​SspiCache\​msnsspc.dll  Version 
HKLM\​System\​CurrentControlSet\​Control\​MediaProperties\​PrivateProperties\​Joystick\​Winmm  wheel 
HKLM\​System\​CurrentControlSet\​Control\​ProductOptions  ProductType  WinNT 
HKLM\​System\​CurrentControlSet\​Control\​SecurityProviders  SecurityProviders  msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll 
HKLM\​System\​CurrentControlSet\​Control\​SecurityProviders\​SaslProfiles  GSSAPI  Kerberos 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  ComSpec  %SystemRoot%\​system32\​cmd.exe 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  FP_NO_HOST_CHECK  NO 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  NUMBER_OF_PROCESSORS 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  OS  Windows_NT 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PATHEXT  .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_ARCHITECTURE  x86 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_IDENTIFIER  x86 Family 6 Model 3 Stepping 3, GenuineIntel 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_LEVEL 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_REVISION  0303 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  Path  %SystemRoot%\​system32;%SystemRoot%;%SystemRoot%\​System32\​Wbem 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TEMP  %SystemRoot%\​TEMP 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TMP  %SystemRoot%\​TEMP 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  windir  %SystemRoot% 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  UseDomainNameDevolution 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Num_Catalog_Entries 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  DisplayString  Tcpip 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  ProviderId  0x409d05229e7ecf11ae5a00aa00a7112b 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  SupportedNameSpace  12 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  DisplayString  NTDS 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  LibraryPath  %SystemRoot%\​System32\​winrnr.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  ProviderId  0xee37263b80e5cf11a55500c04fd8d4ac 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  SupportedNameSpace  32 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  DisplayString  Network Location Awareness (NLA) Namespace 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  ProviderId  0x3a244266a83ba64abaa52e0bd71fdd83 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  SupportedNameSpace  15 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Next_Catalog_Entry_ID  1012 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Num_Catalog_Entries  11 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000001  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000002  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000003  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000004  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000005  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000006  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000007  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000008  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000009  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000010  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000011  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​Setup  SystemSetupInProgress 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TEMP  %USERPROFILE%\​Local Settings\​Temp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TMP  %USERPROFILE%\​Local Settings\​Temp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  CertificateRevocation 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  DisableCachingOfSSLPages 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableHttp1_1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableNegotiate 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  MimeExclusionListForCache  multipart/mixed multipart/x-mixed-replace multipart/x-byteranges  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  SecureProtocols  160 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnPost  0x01000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnZoneCrossing 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Winlogon  ParseAutoexec 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  AppData  %USERPROFILE%\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cache  %USERPROFILE%\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cookies  %USERPROFILE%\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  History  %USERPROFILE%\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Local Settings  %USERPROFILE%\​Local Settings 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Personal  %USERPROFILE%\​My Documents 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache  Signature  Client UrlCache MMF Ver 5.2 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CacheLimit  163410 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CachePrefix   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CachePrefix  Cookie: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheOptions  11 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePath  %USERPROFILE%\​Local Settings\​History\​History.IE5\​MSHist012008051620080517 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePrefix  :2008051620080517:  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheLimit  1000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePath  %USERPROFILE%\​UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePrefix  UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePath  %USERPROFILE%\​Local Settings\​Application Data\​Microsoft\​Feeds Cache 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePrefix  feedplat: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CachePrefix  Visited: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​     
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  @ivt 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  file 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  ftp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  http 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  https 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  shell 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​0  Flags  33 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​1  Flags  475 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​2  Flags  71 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  1A10 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​4  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  MigrateProxy 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings  ProxyEnable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  DefaultConnectionSettings  0x3c0000000200000001000000000000000000000000000000040000000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​windows\​CurrentVersion\​Internet Settings\​Connections  SavedLegacySettings  0x460000006800000001000000000000000000000000000000040000000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  APPDATA  C:\​Documents and Settings\​user\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  CLIENTNAME   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEDRIVE  C: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEPATH  \​Documents and Settings\​user 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMESHARE   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  LOGONSERVER  \​\​USER 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  SESSIONNAME  Console 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  Attributes Change,Value Change,Security Descriptor Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Key Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Key Change 

4.b) kernel32.exe - File Activities

  - Files Deleted:  
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\C4H05OWL\google_com[1].htm

  - Files Created:  
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\C4H05OWL\google_com[1].htm

  - Files Read:  
C:\Documents and Settings\user\Cookies\user@google[3].txt
C:\WINDOWS\system32\dmns.cfg
PIPE\ROUTER
PIPE\lsarpc
c:\autoexec.bat

  - Files Modified:  
Ipinfo
PIPE\ROUTERinfo
PIPE\lsarpcinfo
WMIDataDeviceinfo
\Device\Afd\AsyncConnectHlpinfo
\Device\Afd\Endpointinfo
\Device\Ipinfo
\Device\RasAcdinfo
\Device\Tcpinfo

  - File System Control Communication:  
File Control Code Times
C:\exec  0x00090028 
PIPE\ROUTER  0x0011C017 
PIPE\lsarpc  0x0011C017  26 

  - Device Control Communication:  
File Control Code Times
\Device\KsecDD  0x00390008 
WMIDataDevice  0x0022414C 
WMIDataDevice  0x00228144 
\Device\Tcp  0x00120003 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047)  22 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_GET_SOCK_NAME (0x0001202F) 
\Device\Afd\Endpoint  AFD_SET_INFO (0x0001203B) 
\Device\Afd\AsyncConnectHlp  AFD_CONNECT (0x00012007) 
\Device\Afd\Endpoint  AFD_SELECT (0x00012024) 
unnamed file  0x00120028 
\Device\Afd\Endpoint  AFD_SEND (0x0001201F) 
\Device\Afd\Endpoint  AFD_RECV (0x00012017) 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\System32\mswsock.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
C:\WINDOWS\WindowsShell.Manifest
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\IMM32.DLL
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\RASAPI32.dll
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\msctfime.ime
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\rpcss.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\sensapi.dll
C:\WINDOWS\system32\shell32.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\ws2_32.dll

4.c) kernel32.exe - Process Activities

  - Thread Overview:  
Time Number of threads
After 143 seconds

4.d) kernel32.exe - Network Activity

  - DNS Queries:  
Name Query Type Query Result Successful Protocol
google.com  DNS_TYPE_A  74.125.45.100   
www.google.com  DNS_TYPE_A     
addedantiviruslive.com  DNS_TYPE_A  94.247.2.215   

  -  Unknown TCP Traffic:  
from ANUBIS:1038 to 74.125.45.100:80
State: Connection established, not terminated - Transferred outbound Bytes: 171 - Transferred inbound Bytes: 478
Data sent:
    
4745 5420 2f20 4854 5450 2f31 2e31 0d0a    GET / HTTP/1.1..
5573 6572 2d41 6765 6e74 3a20 6368 656b    User-Agent: chek
0d0a 486f 7374 3a20 676f 6f67 6c65 2e63    ..Host: google.c
6f6d 0d0a 4361 6368 652d 436f 6e74 726f    om..Cache-Contro
6c3a 206e 6f2d 6361 6368 650d 0a43 6f6f    l: no-cache..Coo
6b69 653a 2050 5245 463d 4944 3d66 3363    kie: PREF=ID=f3c
3632 3265 6532 3666 6639 3234 663a 4c44    622ee26ff924f:LD
3d65 6e3a 4352 3d32 3a54 4d3d 3131 3932    =en:CR=2:TM=1192
3732 3235 3833 3a4c 4d3d 3132 3430 3033    722583:LM=124003
3832 3337 3a53 3d42 4a47 6a42 7033 5758    8237:S=BJGjBp3WX
4645 356a 464b 640d 0a0d 0a                FE5jFKd....
Data received:
    
4854 5450 2f31 2e31 2033 3031 204d 6f76    HTTP/1.1 301 Mov
6564 2050 6572 6d61 6e65 6e74 6c79 0d0a    ed Permanently..
4c6f 6361 7469 6f6e 3a20 6874 7470 3a2f    Location: http:/
2f77 7777 2e67 6f6f 676c 652e 636f 6d2f    /www.google.com/
0d0a 436f 6e74 656e 742d 5479 7065 3a20    ..Content-Type: 
7465 7874 2f68 746d 6c3b 2063 6861 7273    text/html; chars
6574 3d55 5446 2d38 0d0a 4461 7465 3a20    et=UTF-8..Date: 
5361 742c 2031 3820 4170 7220 3230 3039    Sat, 18 Apr 2009
2030 373a 3036 3a34 3120 474d 540d 0a45     07:06:41 GMT..E
7870 6972 6573 3a20 4d6f 6e2c 2031 3820    xpires: Mon, 18 
4d61 7920 3230 3039 2030 373a 3036 3a34    May 2009 07:06:4
3120 474d 540d 0a43 6163 6865 2d43 6f6e    1 GMT..Cache-Con
7472 6f6c 3a20 7075 626c 6963 2c20 6d61    trol: public, ma
782d 6167 653d 3235 3932 3030 300d 0a53    x-age=2592000..S
6572 7665 723a 2067 7773 0d0a 436f 6e74    erver: gws..Cont
656e 742d 4c65 6e67 7468 3a20 3231 390d    ent-Length: 219.
0a0d 0a                                    ...
Data received:
    
3c48 544d 4c3e 3c48 4541 443e 3c6d 6574    <HTML><HEAD><met
6120 6874 7470 2d65 7175 6976 3d22 636f    a http-equiv="co
6e74 656e 742d 7479 7065 2220 636f 6e74    ntent-type" cont
656e 743d 2274 6578 742f 6874 6d6c 3b63    ent="text/html;c
6861 7273 6574 3d75 7466 2d38 223e 0a3c    harset=utf-8">.<
5449 544c 453e 3330 3120 4d6f 7665 643c    TITLE>301 Moved<
2f54 4954 4c45 3e3c 2f48 4541 443e 3c42    /TITLE></HEAD><B
4f44 593e 0a3c 4831 3e33 3031 204d 6f76    ODY>.<H1>301 Mov
6564 3c2f 4831 3e0a 5468 6520 646f 6375    ed</H1>.The docu
6d65 6e74 2068 6173 206d 6f76 6564 0a3c    ment has moved.<
4120 4852 4546 3d22 6874 7470 3a2f 2f77    A HREF="http://w
7777 2e67 6f6f 676c 652e 636f 6d2f 223e    ww.google.com/">
6865 7265 3c2f 413e 2e0d 0a3c 2f42 4f44    here</A>...</BOD
593e 3c2f 4854 4d4c 3e0d 0a                Y></HTML>..
Data sent:
    
4745 5420 2f20 4854 5450 2f31 2e31 0d0a    GET / HTTP/1.1..
5573 6572 2d41 6765 6e74 3a20 6368 656b    User-Agent: chek
0d0a 486f 7374 3a20 676f 6f67 6c65 2e63    ..Host: google.c
6f6d 0d0a 4361 6368 652d 436f 6e74 726f    om..Cache-Contro
6c3a 206e 6f2d 6361 6368 650d 0a43 6f6f    l: no-cache..Coo
6b69 653a 2050 5245 463d 4944 3d66 3363    kie: PREF=ID=f3c
3632 3265 6532 3666 6639 3234 663a 4c44    622ee26ff924f:LD
3d65 6e3a 4352 3d32 3a54 4d3d 3131 3932    =en:CR=2:TM=1192
3732 3235 3833 3a4c 4d3d 3132 3430 3033    722583:LM=124003
3832 3337 3a53 3d42 4a47 6a42 7033 5758    8237:S=BJGjBp3WX
4645 356a 464b 640d 0a0d 0a                FE5jFKd....
Data received:
    
4854 5450 2f31 2e31 2033 3031 204d 6f76    HTTP/1.1 301 Mov
6564 2050 6572 6d61 6e65 6e74 6c79 0d0a    ed Permanently..
4c6f 6361 7469 6f6e 3a20 6874 7470 3a2f    Location: http:/
2f77 7777 2e67 6f6f 676c 652e 636f 6d2f    /www.google.com/
0d0a 436f 6e74 656e 742d 5479 7065 3a20    ..Content-Type: 
7465 7874 2f68 746d 6c3b 2063 6861 7273    text/html; chars
6574 3d55 5446 2d38 0d0a 4461 7465 3a20    et=UTF-8..Date: 
5361 742c 2031 3820 4170 7220 3230 3039    Sat, 18 Apr 2009
2030 373a 3037 3a32 3920 474d 540d 0a45     07:07:29 GMT..E
7870 6972 6573 3a20 4d6f 6e2c 2031 3820    xpires: Mon, 18 
4d61 7920 3230 3039 2030 373a 3037 3a32    May 2009 07:07:2
3920 474d 540d 0a43 6163 6865 2d43 6f6e    9 GMT..Cache-Con
7472 6f6c 3a20 7075 626c 6963 2c20 6d61    trol: public, ma
782d 6167 653d 3235 3932 3030 300d 0a53    x-age=2592000..S
6572 7665 723a 2067 7773 0d0a 436f 6e74    erver: gws..Cont
656e 742d 4c65 6e67 7468 3a20 3231 390d    ent-Length: 219.
0a0d 0a                                    ...
Data received:
    
3c48 544d 4c3e 3c48 4541 443e 3c6d 6574    <HTML><HEAD><met
6120 6874 7470 2d65 7175 6976 3d22 636f    a http-equiv="co
6e74 656e 742d 7479 7065 2220 636f 6e74    ntent-type" cont
656e 743d 2274 6578 742f 6874 6d6c 3b63    ent="text/html;c
6861 7273 6574 3d75 7466 2d38 223e 0a3c    harset=utf-8">.<
5449 544c 453e 3330 3120 4d6f 7665 643c    TITLE>301 Moved<
2f54 4954 4c45 3e3c 2f48 4541 443e 3c42    /TITLE></HEAD><B
4f44 593e 0a3c 4831 3e33 3031 204d 6f76    ODY>.<H1>301 Mov
6564 3c2f 4831 3e0a 5468 6520 646f 6375    ed</H1>.The docu
6d65 6e74 2068 6173 206d 6f76 6564 0a3c    ment has moved.<
4120 4852 4546 3d22 6874 7470 3a2f 2f77    A HREF="http://w
7777 2e67 6f6f 676c 652e 636f 6d2f 223e    ww.google.com/">
6865 7265 3c2f 413e 2e0d 0a3c 2f42 4f44    here</A>...</BOD
593e 3c2f 4854 4d4c 3e0d 0a                Y></HTML>..

  -  TCP Connection Attempts:  
from ANUBIS:1039 to 74.125.43.99:80
from ANUBIS:1040 to 94.247.2.215:80
from ANUBIS:1038 to 74.125.45.100:80


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org