Skip to content

Latest commit

 

History

History
82 lines (68 loc) · 1.82 KB

949A2A6D.md

File metadata and controls

82 lines (68 loc) · 1.82 KB

949A2A6D v4.00.09

Environmental Artifacts

argv[0]

C:\Documents and Settings\Administrator\Desktop\Analysis.exe

GetEnvironmentStrings

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=Ikar-Sys-Sim-PC
ComSpec=C:\Windows\System32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\\Ikar-Sys-Sim-PC
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Windows\System32;C:\Windows
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f08
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Windows\Temp
TMP=C:\Windows\Temp
USERDOMAIN=
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
windir=C:\Windows

CreateToolhelp32Snapshot

PPID    PID    Process Name
0       0      System Idle Process
0       4      System
4       548    smss.exe
548     604    csrss.exe
548     628    winlogon.exe
628     672    services.exe
672     880    svchost.exe
672     1324   spoolsv.exe
672     1248   alg.exe
628     684    lsass.exe
0       1688   explorer.exe
1688    1800   iexplore.exe
1688    1964   cmd.exe
1688    1984   Analysis.exe

OS API Inconsistency

GetSystemRegistryQuota

pdwQuotaAllowed and pdwQuotaUsed are not supposed to be null.

DWORD pdwQuotaAllowed = 0x00000000;
DWORD pdwQuotaUsed    = 0x00000000;

GetProcessVersion

0x00050002: Windows Server 2003 R2, Windows Server 2003, Windows XP 64-Bit Edition.

DWORD process_version = GetProcessVersion(0); // => 0x00050002