Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Report generated with Buster Sandbox Analyzer 1.88 at 00:31:38 on 16/10/2015
- Detailed report of suspicious malware actions:
- Checked for debuggers
- Connected to WWW
- Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_f84
- Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_f84
- Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_f84
- Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_f84
- Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_f84
- Created a mutex named: .NETFramework_Perf_Library_Lock_PID_f84
- Created a mutex named: ASP.NET_2.0.50727_Perf_Library_Lock_PID_f84
- Created a mutex named: ASP.NET_4.0.30319_Perf_Library_Lock_PID_f84
- Created a mutex named: ASP.NET_Perf_Library_Lock_PID_f84
- Created a mutex named: aspnet_state_Perf_Library_Lock_PID_f84
- Created a mutex named: ContentFilter_Perf_Library_Lock_PID_f84
- Created a mutex named: ContentIndex_Perf_Library_Lock_PID_f84
- Created a mutex named: CTF.Asm.MutexDefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: CTF.Compart.MutexDefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: CTF.Layouts.MutexDefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: CTF.LBES.MutexDefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: CTF.TimListCache.FMPDefaultS-1-5-21-1275210071-651377827-1801674531-1003MUTEX.DefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: CTF.TMD.MutexDefaultS-1-5-21-1275210071-651377827-1801674531-1003
- Created a mutex named: idm_mkb_count_mutex
- Created a mutex named: idm_mms_count_mutex
- Created a mutex named: ISAPISearch_Perf_Library_Lock_PID_f84
- Created a mutex named: Local\!PrivacIE!SharedMemory!Mutex
- Created a mutex named: Local\_!MSFTHISTORY!_
- Created a mutex named: Local\c:!documents and settings!sab!cookies!
- Created a mutex named: Local\c:!documents and settings!sab!local settings!history!history.ie5!
- Created a mutex named: Local\c:!documents and settings!sab!local settings!temporary internet files!content.ie5!
- Created a mutex named: Local\IDMEventMonitor
- Created a mutex named: Local\ZoneAttributeCacheCounterMutex
- Created a mutex named: Local\ZonesCacheCounterMutex
- Created a mutex named: Local\ZonesCounterMutex
- Created a mutex named: Local\ZonesLockedCacheCounterMutex
- Created a mutex named: MSCTF.Shared.MUTEX.IIP
- Created a mutex named: MSCTF.Shared.MUTEX.MIF
- Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: MSDTC_Perf_Library_Lock_PID_f84
- Created a mutex named: PerfDisk_Perf_Library_Lock_PID_f84
- Created a mutex named: PerfNet_Perf_Library_Lock_PID_f84
- Created a mutex named: PerfOS_Perf_Library_Lock_PID_f84
- Created a mutex named: PerfProc_Perf_Library_Lock_PID_f84
- Created a mutex named: PSched_Perf_Library_Lock_PID_f84
- Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_f84
- Created a mutex named: RSVP_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelEndpoint 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelOperation 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: ServiceModelService 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: Shell.CMruPidlList
- Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: Spooler_Perf_Library_Lock_PID_f84
- Created a mutex named: TapiSrv_Perf_Library_Lock_PID_f84
- Created a mutex named: Tcpip_Perf_Library_Lock_PID_f84
- Created a mutex named: TermService_Perf_Library_Lock_PID_f84
- Created a mutex named: UniqueMutexName
- Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_f84
- Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_f84
- Created process: C:\Documents and Settings\Sab\Desktop\EM\0EM.exe, "C:\Documents and Settings\Sab\Desktop\EM\0EM.exe" , null
- Detected Anti-Malware Analyzer routine: File Monitor detection
- Detected Anti-Malware Analyzer routine: OllyDbg detection
- Detected keylogger functionality
- Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001
- Got computer name
- Got input locale identifiers
- Got user name information
- Got volume information
- Installs a hook procedure that monitors keystroke messages
- Installs a hook procedure that monitors mouse messages
- Slept over 2 minutes
- Transfered files from and/or to internet
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement