• Values Created
Name Type Size Value
LM\System\CurrentControlSet\Services\UPDATEDATA\DisplayName REG_SZ 22 "UPDATEDATA"
LM\System\CurrentControlSet\Services\UPDATEDATA\Enum\0 REG_SZ 56 "Root\LEGACY_UPDATEDATA\0000"
LM\System\CurrentControlSet\Services\UPDATEDATA\Enum\Count REG_DWORD 4 0x1
LM\System\CurrentControlSet\Services\UPDATEDATA\Enum\NextInstance REG_DWORD 4 0x1
LM\System\CurrentControlSet\Services\UPDATEDATA\ErrorControl REG_DWORD 4 0x0
LM\System\CurrentControlSet\Services\UPDATEDATA\ImagePath REG_EXPAND_SZ 86 "\??\C:\WINDOWS\system32\drivers\acpiec.sys"
LM\System\CurrentControlSet\Services\UPDATEDATA\Security\Security REG_BINARY 168 ?
LM\System\CurrentControlSet\Services\UPDATEDATA\Start REG_DWORD 4 0x3
LM\System\CurrentControlSet\Services\UPDATEDATA\Type REG_DWORD 4 0x1
• Files Created
Name Size Last Write Time Creation Time Last Access Time Attr
C:\WINDOWS\system32\func.dll 36864 2009.01.12 14:48:00.968 2009.01.12 14:48:00.921 2009.01.12 14:48:00.921 0x20
• Files Changed
Name Size Last Write Time Creation Time Last Access Time Attr
C:\WINDOWS\system32\drivers\acpiec.sys 11648/13056 2007.07.27 12:00:00.000/2009.01.12 14:48:03.203 2007.07.27 12:00:00.000/2007.07.27 12:00:00.000 2008.08.01 04:46:06.655/2008.08.01 04:46:06.655 0x20/0x20
• Drivers Loaded
Base Size Flags Image Name
0xf8dfa000 0x4000 0x9104000 \??\C:\WINDOWS\system32\drivers\acpiec.sys
• Drivers Unloaded
• Processes Created
PId Process Name Image Name
0x420 rundll32.exe C:\WINDOWS\system32\rundll32.exe
0x770 wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
• Processes Terminated
• Threads Created
PId Process Name TId Start Start Mem Win32 Start Win32 Start Mem
0x25c csrss.exe 0x7e4 0x75b44616 MEM_IMAGE 0x0 MEM_PRIVATE
0x274 winlogon.exe 0x444 0x7c810856 MEM_IMAGE 0x76c74a65 MEM_IMAGE
0x274 winlogon.exe 0x484 0x7c810856 MEM_IMAGE 0x77a8964a MEM_IMAGE
0x344 svchost.exe 0x170 0x7c810856 MEM_IMAGE 0x7c910760 MEM_IMAGE
0x404 svchost.exe 0xdc 0x7c810856 MEM_IMAGE 0x606b73ae MEM_IMAGE
0x404 svchost.exe 0x298 0x7c810856 MEM_IMAGE 0x762cf010 MEM_IMAGE
0x404 svchost.exe 0x32c 0x7c810856 MEM_IMAGE 0x762cf010 MEM_IMAGE
0x404 svchost.exe 0x360 0x7c810856 MEM_IMAGE 0x762cf0a3 MEM_IMAGE
0x404 svchost.exe 0x364 0x7c810856 MEM_IMAGE 0x4156 MEM_FREE
0x404 svchost.exe 0x3fc 0x7c810856 MEM_IMAGE 0x606b73ae MEM_IMAGE
0x404 svchost.exe 0x42c 0x7c810856 MEM_IMAGE 0x774f319a MEM_IMAGE
0x404 svchost.exe 0x46c 0x7c810856 MEM_IMAGE 0x606b73ae MEM_IMAGE
0x404 svchost.exe 0x470 0x7c810856 MEM_IMAGE 0x7529e44b MEM_IMAGE
0x404 svchost.exe 0x4c4 0x7c810856 MEM_IMAGE 0x7c929fae MEM_IMAGE
0x404 svchost.exe 0x4e4 0x7c810856 MEM_IMAGE 0x7529edb3 MEM_IMAGE
0x404 svchost.exe 0x63c 0x7c810856 MEM_IMAGE 0x40dd MEM_FREE
0x404 svchost.exe 0x744 0x7c810856 MEM_IMAGE 0x762cf010 MEM_IMAGE
0x404 svchost.exe 0x7d4 0x7c810856 MEM_IMAGE 0x606b73ae MEM_IMAGE
0x420 rundll32.exe 0x674 0x7c810867 MEM_IMAGE 0x1001bdc MEM_IMAGE
0x770 wmiprvse.exe 0x380 0x7c810856 MEM_IMAGE 0x5f771c49 MEM_IMAGE
0x770 wmiprvse.exe 0x400 0x7c810856 MEM_IMAGE 0x774f319a MEM_IMAGE
0x770 wmiprvse.exe 0x4a8 0x7c810856 MEM_IMAGE 0x0 MEM_FREE
0x770 wmiprvse.exe 0x4c8 0x7c810856 MEM_IMAGE 0x77e76bf0 MEM_IMAGE
0x770 wmiprvse.exe 0x578 0x7c810856 MEM_IMAGE 0x100ce42 MEM_IMAGE
0x770 wmiprvse.exe 0x66c 0x7c810856 MEM_IMAGE 0x716df2be MEM_IMAGE
0x770 wmiprvse.exe 0x760 0x7c810856 MEM_IMAGE 0x0 MEM_FREE
0x770 wmiprvse.exe 0x794 0x7c810856 MEM_IMAGE 0x0 MEM_FREE
0x770 wmiprvse.exe 0x7c0 0x7c810867 MEM_IMAGE 0x1024636 MEM_IMAGE
• Modules Loaded
PId Process Name Base Size Flags Image Name
0x344 svchost.exe 0x76fd0000 0x7f000 0x800c4004 C:\WINDOWS\system32\CLBCATQ.DLL
0x344 svchost.exe 0x77050000 0xc5000 0x800c4006 C:\WINDOWS\system32\COMRes.dll
0x344 svchost.exe 0x77b40000 0x22000 0x800c4004 C:\WINDOWS\system32\Apphelp.dll
0x404 svchost.exe 0x73d30000 0x17000 0x800c4004 C:\WINDOWS\system32\wbem\wbemcons.dll
0x404 svchost.exe 0x74ed0000 0xe000 0x80084004 C:\WINDOWS\system32\wbem\wbemsvc.dll
• Windows Api Calls
PId Image Name Address Function ( Parameters ) | Return Value
0x420 C:\WINDOWS\system32\rundll32.exe 0x923e57 CreateServiceA(hSCManager: 0x98e08, lpServiceName: "UPDATEDATA", lpDisplayName: "UPDATEDATA", dwDesiredAccess: 0x10, dwServiceType: 0x1, dwStartType: 0x3, dwErrorControl: 0x0, lpBinaryPathName: "C:\WINDOWS\system32\drivers\acpiec.sys", lpLoadOrderGroup: "(null)", lpdwTagId: 0x0, lpDependencies: 0x0, lpServiceStartName: "(null)", lpPassword: 0x0)|0x9b0b8
• Verdict
Auto Analysis Verdict
Rated as Suspicious
• Description
Suspicious Actions Detected
Creates files in windows system directory
Creates system services or drivers
Load system drivers
Patches system files |