My SandBox Report:
General information
File Name:c:\bulubebek.exe
MD5:EE090E490F48BBA5EA76ADBFAE632256
SHA-1:d7127f18f99678c83a0240e1a28960b956f69bdc
File Size:53328 Bytes
Packed:*** Unknown EXE
+ Antivirus Detection
Antivir:Contains detection pattern of the worm WORM/Autorun.MMX.11
AVG:Found Nothing
F-Prot:Found Nothing
Avast:Win32:AutoRun-APJ [Wrm
BitDefender: Worm.Generic.47303
ClamAV:Found Nothing
+ File Identifier
68.0% (.EXE) Win32 Executable Generic (8527/13/3) 15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable Generic (2000/1)
0.0% (.CEL) Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3)
68.0% (.EXE) Win32 Executable Generic (8527/13/3) 15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable Generic (2000/1)
0.0% (.CEL) Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3)
+ String Found
!T6.032rogra1.4298.7585.420 in DOS mode.
.text
.data
.rsrc
MSVBVM60.DLL
MSVBVM60.DLL
Ps;uQs
nOsmYOs
Qs[TPsp
Ps]TDs
Project1
FILES
BULUBEBEK
mllllllllllllllllllllllllll
`__________________________
`TTTTTTTTTTTTTTTTTTTTTTTTTT
VUUUUUUUUUUUUUUUUUUUUUUUUUU
WHHHHHHHHHHHHHHHHHHHHHHHHHH
J>>>>>>>>>>>>>>>>>>>>>>>>>>
@88888888888888888888888888
A44444444444444444444444444
K$$$$$$$$$$$$$$$$$$$$$$$$$$
NC;1*
I>>>GR]ht
9444444444=Q
3FPje
#7FPje
nnnnXn
*************
)))))))))
)))))
"))))
P`dpoWvww
PD,:GZbjnXrwww
PI+88888AK\gqlswww
P`#888888888?G[epmtvww
''''''''''''''@Lcklw
'''''''''''''''''8pw
%%%%%%%%%%%%%%%%%8ew
%%%%%%%%%%%%%%%%%8euw
'Ksw
'Ktw
B$[bU<)
&7JYc>
LbUE/
"(FLafU>/*Q
)310.
f661ES
Form1
Timer5
PROTK
Hancurkan
Timer4
SysPath
winPath
Text2
Timer3
List3
Timer2
List1
Text1
Text1
Timer1
List2
BULUBEBEK
Project1
Project1
XFILES
Module1
ModRegistry
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
List3
List1
+ File And Folder Activity
Files Added
C:\WINDOWS\system32\SCRIPT.exe
C:\WINDOWS\LSASS.exe
C:\bulubebek.exe
+ Registry Changes
Key Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System
Value Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\CheckedValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\DefaultValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\UncheckedValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\DefaultValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\CheckedValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\UncheckedValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\CheckedValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\DefaultValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\UncheckedValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\DefaultValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\CheckedValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\UncheckedValue: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NPF\0000\Control\ActiveService: "NPF"
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Command Processor\Autorun: "exit"
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: "explorer.exe script.exe"
Value Modified
HKLM\SOFTWARE\Microsoft\Command Processor\AutoRun: ""
HKLM\SOFTWARE\Microsoft\Command Processor\AutoRun: "exit"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\DefaultValue: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\DefaultValue: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "Explorer.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "explorer.exe script.exe"
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: 0x00000002
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt: 0x00000000
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden: 0x00000000
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress: 0x00000001
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress: 0x00000000