Full Analysis Report of namebench-1.3.1-windows.exe

Summary:

  • Summary of the findings

      No. What's been found Severity

Technical details:

  • General

    • User : \\TEST-R7CHD9Q826\Administrator
    • Application type :
    • Priority : Normal
    • Size : 0
    • Path : C:\Samples\namebench-1.3.1-windows.exe
    • Command : "C:\Samples\namebench-1.3.1-windows.exe"
    • MD5:
    • SHA1:
    • Version details

      • Company :
      • File version :
      • Product version :
      • Desciption :
      • Product name :
      • Legal copyright :
      • Internal name :
    • File times

      • Creation time : Thursday, January 01, 1970 - 08:00:00
      • Modification time : Thursday, January 01, 1970 - 08:00:00
      • Last access time : Thursday, January 01, 1970 - 08:00:00
    • Process times

      • Start time : 15 : 47 : 27
      • Exit time : 15 : 47 : 46
      • Kernel time : 0.140625 (s)
      • User time : 0.031250 (s)
    • IO counters

      • Read operation : 6929
      • Write operation : 5
      • Other operation : 821
      • Read transfer : 39192
      • Write transfer : 1262
      • Other transfer : 63060
    • Memory details

      • Page fault count : 953
      • Page file usage : 0
      • Peak page file usage : 1171456
      • Peak working set size : 3571712
      • Quota non paged pool usage : 0
      • Quota paged pool usage : 0
      • Quota peak non paged pool usage : 2520
      • Quota peak paged pool usage : 64588
      • Working set size : 28672
    • Process privileges

      • SeChangeNotifyPrivilege
      • SeSecurityPrivilege
      • SeBackupPrivilege
      • SeRestorePrivilege
      • SeSystemtimePrivilege
      • SeShutdownPrivilege
      • SeRemoteShutdownPrivilege
      • SeTakeOwnershipPrivilege
      • SeDebugPrivilege
      • SeSystemEnvironmentPrivilege
      • SeSystemProfilePrivilege
      • SeProfileSingleProcessPrivilege
      • SeIncreaseBasePriorityPrivilege
      • SeLoadDriverPrivilege
      • SeCreatePagefilePrivilege
      • SeIncreaseQuotaPrivilege
      • SeUndockPrivilege
      • SeManageVolumePrivilege
      • SeImpersonatePrivilege
      • SeCreateGlobalPrivilege
  • Events statistics

      Event Count
      SetValueKey 1
      Process Create 1
      Process Exit 1
      Thread Create 1
      Thread Exit 1
      Load Image 19
  • Modules

      Index Name Path Load Address Image Size Entry Point Version Size Company Description
      1 ntdll.dll %System%\ntdll.dll 0x7C930000 0xD2000 0x00000000 5.2.3790.3290 (srv03_sp1_gdr.090203-1205) 841216 Microsoft Corporation NT Layer DLL
      2 KERNEL32.dll %System%\kernel32.dll 0x7C800000 0x12C000 0x7C825FB4 5.2.3790.3311 (srv03_sp1_gdr.090321-1245) 1206784 Microsoft Corporation Windows NT BASE API Client DLL
      3 ADVAPI32.dll %System%\advapi32.dll 0x77F30000 0xAC000 0x77F4DFCD 5.2.3790.3290 (srv03_sp1_gdr.090203-1205) 686592 Microsoft Corporation Advanced Windows 32 Base API
      4 RPCRT4.dll %System%\rpcrt4.dll 0x77C20000 0x9F000 0x77C45061 5.2.3790.2971 (srv03_sp1_gdr.070709-2334) 642560 Microsoft Corporation Remote Procedure Call Runtime
      5 GDI32.dll %System%\gdi32.dll 0x77BD0000 0x49000 0x77BDB23E 5.2.3790.3233 (srv03_sp1_gdr.081022-1216) 286208 Microsoft Corporation GDI Client DLL
      6 USER32.dll %System%\user32.dll 0x77E10000 0x91000 0x77E1947C 5.2.3790.2892 (srv03_sp1_gdr.070301-0030) 584192 Microsoft Corporation Windows USER API Client DLL
      7 ole32.dll %System%\ole32.dll 0x774B0000 0x134000 0x774F5C37 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 1244672 Microsoft Corporation Microsoft OLE for Windows
      8 msvcrt.dll %System%\msvcrt.dll 0x77B70000 0x5A000 0x77B7F78B 7.0.3790.1830 (srv03_sp1_rtm.050324-1447) 348672 Microsoft Corporation Windows NT CRT DLL
      9 shell32.dll %System%\shell32.dll 0x7CA10000 0x7E1000 0x7CA90660 6.00.3790.3158 (srv03_sp1_gdr.080617-1231) 8242176 Microsoft Corporation Windows Shell Common Dll
      10 SHLWAPI.dll %System%\shlwapi.dll 0x77EB0000 0x52000 0x77ED86F9 6.00.3790.3304 (srv03_sp1_gdr.090303-1204) 320512 Microsoft Corporation Shell Light-weight Utility Library
      11 IMM32.DLL %System%\imm32.dll 0x76180000 0x1D000 0x761812D0 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 110592 Microsoft Corporation Windows IMM32 API Client DLL
      12 LPK.DLL %System%\lpk.dll 0x63090000 0x9000 0x63092EB2 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 22016 Microsoft Corporation Language Pack
      13 USP10.dll %System%\usp10.dll 0x74AE0000 0x61000 0x74B189AC 1.0422.3790.1830 (srv03_sp1_rtm.050324-1447) 364032 Microsoft Corporation Uniscribe Unicode script processor
      14 Comctl32.dll %Windir%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.1830_x-ww_7AE38CCF\comctl32.dll 0x77CD0000 0x103000 0x77D5A81E 6.0 (srv03_sp1_rtm.050324-1447) 1051136 Microsoft Corporation User Experience Controls Library
      15 MSCTF.dll %System%\MSCTF.dll 0x4B210000 0x51000 0x4B2113EE 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 317440 Microsoft Corporation MSCTF Server DLL
      16 apphelp.dll %System%\apphelp.dll 0x75D60000 0x27000 0x75D61239 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 150016 Microsoft Corporation Application Compatibility Client Library
      17 msctfime.ime %System%\MSCTFIME.IME 0x4C510000 0x2E000 0x4C529F5D 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 177152 Microsoft Corporation Microsoft Text Frame Work Service IME

       

  • File system modifications

  • Memory modifications

  • Registry modifications

    • The following Registry value was modified:

      • H = 4
  • Network activity

  • How to protect yourself in the future

This report was created with Ax3soft Scout.