Sign In|Create an account

xandora.net - Suspicious File Analyzer

Home|Upload Files|Blog|Technology|Services|Team


HEUR:Trojan.Win32.Generic
File Details
MD5b31e4624cdc45655b468921823e1b72b
SHA-116f2fd51a5f00e2d220adc0c5db684e40ac5bde7
File Typeexe
First Received (GMT+8)2011-06-23 16:42:00
Size (bytes)134144
Weightage101
virustotal.com18 vendors detected
 
Static File Header
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 4DFA632F Fri Jun 17 04:10:23 2011
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 00024000
Code Base: 00001000 Size: 00007600
Data Base: 00009000 Size: 00019200
Entry Point: 00002601 (file offset 00001A01)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: .text RVA: 00001000 Offset: 00000400 Size: 00007600 Flags: 60000020 (CER)
2: .rdata RVA: 00009000 Offset: 00007A00 Size: 00001C00 Flags: 40000040 (DR)
3: .data RVA: 0000B000 Offset: 00009600 Size: 00001200 Flags: C0000040 (DRW)
4: .rsrc RVA: 0000D000 Offset: 0000A800 Size: 00016400 Flags: 40000040 (DR)
 
Filesystem Change
MD5Filename
0x94f3d031f48fdb8334878576113d81a5"/WINDOWS/system32/userdiff.sav"
 
Registry Change
ActionRegistry
Changedsoftware_Microsoft_DeviceControl
Addedsoftware_Microsoft_DataFactory_HandlerInfo_SafeHandlerList_MSDFMAP_VC.Handler
Addedsoftware_Microsoft_DeviceManager
Addedsoftware_Microsoft_DeviceManager_BusTypes
Addedsoftware_Microsoft_Windows_CurrentVersion_Group_Policy_State_Machine_Extension-List
Addedsoftware_Microsoft_Windows_CurrentVersion_Group_Policy_State_Machine_Extension-List
Addedsoftware_Microsoft_Windows_CurrentVersion_Group_Policy_State_S-1-5-21-790525478-1390067357-1417001333-500_Extension-List
Addedsoftware_Microsoft_Windows_CurrentVersion_Group_Policy_State_S-1-5-21-790525478-1390067357-1417001333-500_Extension-List
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_AeDebug
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_AeDebug
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_Prefetcher
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_ProfileList
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_Prefetcher
Addedsoftware_Microsoft_Windows_NT_CurrentVersion_ProfileList
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Applets_SysTray
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Applets_SysTray
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_CD_Burning_Drives
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_CLSID
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_CD_Burning_Drives
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_CLSID
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Desktop
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Desktop_CleanupWiz
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Desktop
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Desktop_CleanupWiz
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_Component_Categories_{00021493-0000-0000-C000-000000000046}_Enum
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_Component_Categories_{00021493-0000-0000-C000-000000000046}_Enum
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_Component_Categories_{00021494-0000-0000-C000-000000000046}_Enum
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_ShellNew
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_Component_Categories_{00021494-0000-0000-C000-000000000046}_Enum
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_Discardable_PostSetup_ShellNew
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_RunMRU
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_RunMRU
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_UserAssist_{5E6AB780-7743-11CF-A12B-00AA004AE837}_Count
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_UserAssist_{5E6AB780-7743-11CF-A12B-00AA004AE837}_Count
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_UserAssist_{75048700-EF1F-11D0-9888-006097DEACF9}_Count
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Explorer_UserAssist_{75048700-EF1F-11D0-9888-006097DEACF9}_Count
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Ext_Stats_{02478D38-C3F9-4EFB-9B51-7695ECA05670}_iexplore
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Ext_Stats_{02478D38-C3F9-4EFB-9B51-7695ECA05670}_iexplore
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_Run
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_RunOnce
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_WindowsUpdate
AddedNTUSER_Software_Microsoft_Windows_CurrentVersion_WinTrust
 
Running Processes
PIDCommand
288smss.exe
392csrss.exe
416winlogon.exe
532services.exe
544lsass.exe
700svchost.exe
744svchost.exe
804svchost.exe
848svchost.exe
896svchost.exe
1080explorer.exe
1584alg.exe
212svchost.exe
 
Traffic - by TCP/IP Connections