<?xml version="1.0"?>
<!-- This analysis was created by CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="1.107" time="18.04.2007 20:09:24" file="6dc8e20061a5368d11e1b42f18e8f522.exe" logpath="C:\analysis\log\6dc8e20061a5368d11e1b42f18e8f522.exe\run_1\">
<calltree>
<process_call index="1" pid="1012" filename="c:\6dc8e20061a5368d11e1b42f18e8f522.exe" starttime="00:00.172" startreason="AnalysisTarget"><calltree>
<process_call index="2" pid="1620" filename="C:\WINDOWS\Explorer.EXE" starttime="00:03.156" startreason="InjectedCode"/>
</calltree>
</process_call>

</calltree>

<processes>
<process index="1" pid="1012" filename="c:\6dc8e20061a5368d11e1b42f18e8f522.exe" filesize="28672" md5="6dc8e20061a5368d11e1b42f18e8f522" username="nepenthes" parentindex="0" starttime="00:00.172" terminationtime="00:30.469" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="3122">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="31917">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.10-36" signature_file_version="6.38.1.8">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\6dc8e20061a5368d11e1b42f18e8f522.exe" successful="1" address="&#x24;400000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1" address="&#x24;77D10000" size="589824"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1" address="&#x24;77EF0000" size="290816"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1" address="&#x24;77E50000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1" address="&#x24;770F0000" size="573440"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1" address="&#x24;77BE0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1" address="&#x24;5D450000" size="630784"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1" address="&#x24;71A30000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1" address="&#x24;71A10000" size="94208"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1" address="&#x24;71A00000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1" address="&#x24;5E490000" size="53248"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1" address="&#x24;76AD0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1" address="&#x24;590B0000" size="28672"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
</dll_handling_section>
<process_section>
<open_process filename="C:\WINDOWS\Explorer.EXE" targetpid="1620" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_PROCESS,PROCESS_CREATE_THREAD,PROCESS_DUP_HANDLE,PROCESS_QUERY_INFORMATION,PROCESS_SET_INFORMATION,PROCESS_TERMINATE,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE,PROCESS_SET_SESSIONID,PROCESS_SET_QUOTA,SYNCHRONIZE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\Explorer.EXE" targetpid="1620" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<kill_process targetpid="1012" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
<thread_section>
<create_thread_remote targetpid="1620" threadid="1032" address="&#x24;7C801D77" parameteraddress="&#x24;00E30000" creationflags="CREATE_SUSPENDED"/>
<set_thread_context targetpid="1620" threadid="1660" eip="&#x24;00F60000"/>
</thread_section>
<virtual_memory_section>
<vm_allocate targetpid="1620" wantedaddress="&#x24;00000000" address="&#x24;00E30000" wantedsize="11" size="4096" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00E30000" address="&#x24;00E30000" wantedsize="11" size="4096" protect="PAGE_EXECUTE_READWRITE" behavior="Normal"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00E30000" address="&#x24;00E30000" wantedsize="4096" size="4096" protect="PAGE_READWRITE" behavior="Normal"/>
<vm_write targetpid="1620" address="&#x24;00E30000" size="11" behavior="Normal"/>
<vm_allocate targetpid="1620" wantedaddress="&#x24;00000000" address="&#x24;01D20000" wantedsize="1048576" size="1048576" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1620" wantedaddress="&#x24;01E1E000" address="&#x24;01E1E000" wantedsize="8192" size="8192" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;01E1E000" address="&#x24;01E1E000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD" behavior="Normal"/>
<vm_allocate targetpid="1620" wantedaddress="&#x24;00000000" address="&#x24;00EC0000" wantedsize="11" size="4096" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_allocate targetpid="1620" wantedaddress="&#x24;00000000" address="&#x24;00F60000" wantedsize="32" size="4096" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00EC0000" address="&#x24;00EC0000" wantedsize="10" size="4096" protect="PAGE_EXECUTE_READWRITE" behavior="Normal"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00EC0000" address="&#x24;00EC0000" wantedsize="4096" size="4096" protect="PAGE_READWRITE" behavior="Normal"/>
<vm_write targetpid="1620" address="&#x24;00EC0000" size="10" behavior="Normal"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00F60000" address="&#x24;00F60000" wantedsize="32" size="4096" protect="PAGE_EXECUTE_READWRITE" behavior="Normal"/>
<vm_protect targetpid="1620" wantedaddress="&#x24;00F60000" address="&#x24;00F60000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE" behavior="Normal"/>
<vm_write targetpid="1620" address="&#x24;00F60000" size="32" behavior="Normal"/>
</virtual_memory_section>
<window_section>
<find_window classname="Shell_TrayWnd"/>
</window_section>
</process>
<process index="2" pid="1620" filename="C:\WINDOWS\Explorer.EXE" filesize="1035264" md5="22fe1be02eadde1632e478e4125639e0" username="nepenthes" parentindex="1" starttime="00:03.156" terminationtime="02:01.047" startreason="InjectedCode" terminationreason="Timeout" executionstatus="OK">
<dll_handling_section>
<load_dll dll="C:\WINDOWS\Explorer.EXE" successful="1" address="&#x24;1000000" size="1044480"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1" address="&#x24;77BE0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1" address="&#x24;77E50000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1" address="&#x24;77EF0000" size="290816"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1" address="&#x24;77D10000" size="589824"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1" address="&#x24;77F40000" size="483328"/>
<load_dll dll="C:\WINDOWS\system32\SHELL32.dll" successful="1" address="&#x24;7C9D0000" size="8515584"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.dll" successful="1" address="&#x24;770F0000" size="573440"/>
<load_dll dll="C:\WINDOWS\system32\BROWSEUI.dll" successful="1" address="&#x24;75F20000" size="1036288"/>
<load_dll dll="C:\WINDOWS\system32\SHDOCVW.dll" successful="1" address="&#x24;7E1E0000" size="1503232"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1" address="&#x24;77A50000" size="610304"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1" address="&#x24;77AF0000" size="73728"/>
<load_dll dll="C:\WINDOWS\system32\CRYPTUI.dll" successful="1" address="&#x24;76880000" size="544768"/>
<load_dll dll="C:\WINDOWS\system32\WINTRUST.dll" successful="1" address="&#x24;76BF0000" size="188416"/>
<load_dll dll="C:\WINDOWS\system32\IMAGEHLP.dll" successful="1" address="&#x24;76C50000" size="163840"/>
<load_dll dll="C:\WINDOWS\system32\NETAPI32.dll" successful="1" address="&#x24;597D0000" size="344064"/>
<load_dll dll="C:\WINDOWS\system32\WININET.dll" successful="1" address="&#x24;77180000" size="684032"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1" address="&#x24;76F20000" size="184320"/>
<load_dll dll="C:\WINDOWS\system32\VERSION.dll" successful="1" address="&#x24;77BD0000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\UxTheme.dll" successful="1" address="&#x24;5B0F0000" size="229376"/>
<load_dll dll="C:\WINDOWS\system32\ShimEng.dll" successful="1" address="&#x24;5CF00000" size="155648"/>
<load_dll dll="C:\WINDOWS\AppPatch\AcGenral.DLL" successful="1" address="&#x24;6FD90000" size="1875968"/>
<load_dll dll="C:\WINDOWS\system32\WINMM.dll" successful="1" address="&#x24;76AF0000" size="188416"/>
<load_dll dll="C:\WINDOWS\system32\MSACM32.dll" successful="1" address="&#x24;77BB0000" size="86016"/>
<load_dll dll="C:\WINDOWS\system32\USERENV.dll" successful="1" address="&#x24;76620000" size="741376"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1" address="&#x24;773A0000" size="1060864"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1" address="&#x24;5D450000" size="630784"/>
<load_dll dll="C:\WINDOWS\system32\appHelp.dll" successful="1" address="&#x24;77B10000" size="139264"/>
<load_dll dll="C:\WINDOWS\system32\CLBCATQ.DLL" successful="1" address="&#x24;76F90000" size="520192"/>
<load_dll dll="C:\WINDOWS\system32\COMRes.dll" successful="1" address="&#x24;77010000" size="864256"/>
<load_dll dll="C:\WINDOWS\System32\cscui.dll" successful="1" address="&#x24;779F0000" size="352256"/>
<load_dll dll="C:\WINDOWS\System32\CSCDLL.dll" successful="1" address="&#x24;765A0000" size="118784"/>
<load_dll dll="C:\WINDOWS\system32\themeui.dll" successful="1" address="&#x24;5B9B0000" size="466944"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\MSIMG32.dll" successful="1" address="&#x24;76320000" size="20480"/>
<load_dll dll="C:\WINDOWS\system32\xpsp2res.dll" successful="1" address="&#x24;20000000" size="2985984"/>
<load_dll dll="C:\WINDOWS\system32\msutb.dll" successful="1" address="&#x24;60010000" size="208896"/>
<load_dll dll="C:\WINDOWS\system32\MSCTF.dll" successful="1" address="&#x24;746A0000" size="307200"/>
<load_dll dll="C:\WINDOWS\system32\LINKINFO.dll" successful="1" address="&#x24;76930000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\ntshrui.dll" successful="1" address="&#x24;76940000" size="155648"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1" address="&#x24;76AD0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\urlmon.dll" successful="1" address="&#x24;7DF20000" size="655360"/>
<load_dll dll="C:\WINDOWS\system32\WINSTA.dll" successful="1" address="&#x24;76300000" size="65536"/>
<load_dll dll="C:\WINDOWS\system32\webcheck.dll" successful="1" address="&#x24;74AB0000" size="294912"/>
<load_dll dll="C:\WINDOWS\system32\WSOCK32.dll" successful="1" address="&#x24;71A30000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1" address="&#x24;71A10000" size="94208"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1" address="&#x24;71A00000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\stobject.dll" successful="1" address="&#x24;765C0000" size="135168"/>
<load_dll dll="C:\WINDOWS\system32\BatMeter.dll" successful="1" address="&#x24;74A70000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\POWRPROF.dll" successful="1" address="&#x24;74A50000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\SETUPAPI.dll" successful="1" address="&#x24;778F0000" size="999424"/>
<load_dll dll="C:\WINDOWS\system32\WTSAPI32.dll" successful="1" address="&#x24;76F10000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\NETSHELL.dll" successful="1" address="&#x24;763A0000" size="1748992"/>
<load_dll dll="C:\WINDOWS\system32\rtutils.dll" successful="1" address="&#x24;76E40000" size="57344"/>
<load_dll dll="C:\WINDOWS\system32\credui.dll" successful="1" address="&#x24;76BC0000" size="192512"/>
<load_dll dll="C:\WINDOWS\system32\iphlpapi.dll" successful="1" address="&#x24;76D20000" size="102400"/>
<load_dll dll="C:\WINDOWS\system32\MPR.dll" successful="1" address="&#x24;71A80000" size="73728"/>
<load_dll dll="C:\WINDOWS\System32\drprov.dll" successful="1" address="&#x24;75F00000" size="28672"/>
<load_dll dll="C:\WINDOWS\System32\ntlanman.dll" successful="1" address="&#x24;71B90000" size="57344"/>
<load_dll dll="C:\WINDOWS\System32\NETUI0.dll" successful="1" address="&#x24;71C50000" size="94208"/>
<load_dll dll="C:\WINDOWS\System32\NETUI1.dll" successful="1" address="&#x24;71C10000" size="262144"/>
<load_dll dll="C:\WINDOWS\System32\NETRAP.dll" successful="1" address="&#x24;71C00000" size="28672"/>
<load_dll dll="C:\WINDOWS\System32\SAMLIB.dll" successful="1" address="&#x24;71B70000" size="77824"/>
<load_dll dll="C:\WINDOWS\System32\davclnt.dll" successful="1" address="&#x24;75F10000" size="36864"/>
<load_dll dll="C:\WINDOWS\system32\msi.dll" successful="1" address="&#x24;16F0000" size="2908160"/>
<load_dll dll="C:\WINDOWS\system32\rsaenh.dll" successful="1" address="&#x24;FFD0000" size="163840"/>
<load_dll dll="C:\WINDOWS\system32\SXS.DLL" successful="1" address="&#x24;76970000" size="724992"/>
<load_dll dll="C:\WINDOWS\system32\browselc.dll" successful="1" address="&#x24;1A40000" size="77824"/>
<load_dll dll="C:\WINDOWS\system32\MSGINA.dll" successful="1" address="&#x24;75910000" size="1019904"/>
<load_dll dll="C:\WINDOWS\system32\ODBC32.dll" successful="1" address="&#x24;745D0000" size="249856"/>
<load_dll dll="C:\WINDOWS\system32\comdlg32.dll" successful="1" address="&#x24;76350000" size="303104"/>
<load_dll dll="C:\WINDOWS\system32\odbcint.dll" successful="1" address="&#x24;1C00000" size="102400"/>
<load_dll dll="C:\WINDOWS\system32\DUSER.dll" successful="1" address="&#x24;6C670000" size="315392"/>
<load_dll dll="C:\WINDOWS\system32\MLANG.dll" successful="1" address="&#x24;75DC0000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\RASDLG.dll" successful="1" address="&#x24;754D0000" size="700416"/>
<load_dll dll="C:\WINDOWS\system32\MPRAPI.dll" successful="1" address="&#x24;76D00000" size="98304"/>
<load_dll dll="C:\WINDOWS\system32\ACTIVEDS.dll" successful="1" address="&#x24;77C90000" size="208896"/>
<load_dll dll="C:\WINDOWS\system32\adsldpc.dll" successful="1" address="&#x24;76DD0000" size="151552"/>
<load_dll dll="C:\WINDOWS\system32\RASAPI32.dll" successful="1" address="&#x24;76EA0000" size="245760"/>
<load_dll dll="C:\WINDOWS\system32\rasman.dll" successful="1" address="&#x24;76E50000" size="73728"/>
<load_dll dll="C:\WINDOWS\system32\TAPI32.dll" successful="1" address="&#x24;76E70000" size="192512"/>
<load_dll dll="C:\WINDOWS\system32\hnetcfg.dll" successful="1" address="&#x24;66710000" size="364544"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemprox.dll" successful="1" address="&#x24;74E70000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemcomn.dll" successful="1" address="&#x24;75210000" size="225280"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemsvc.dll" successful="1" address="&#x24;74E50000" size="57344"/>
<load_dll dll="C:\WINDOWS\system32\wbem\fastprox.dll" successful="1" address="&#x24;75620000" size="483328"/>
<load_dll dll="C:\WINDOWS\system32\MSVCP60.dll" successful="1" address="&#x24;76020000" size="413696"/>
<load_dll dll="C:\WINDOWS\system32\NTDSAPI.dll" successful="1" address="&#x24;76750000" size="77824"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1" address="&#x24;76EE0000" size="159744"/>
<load_dll dll="C:\WINDOWS\system32\netcfgx.dll" successful="1" address="&#x24;75580000" size="643072"/>
<load_dll dll="C:\WINDOWS\system32\CLUSAPI.dll" successful="1" address="&#x24;76D60000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\netman.dll" successful="1" address="&#x24;77CD0000" size="208896"/>
<load_dll dll="C:\WINDOWS\system32\WZCSAPI.DLL" successful="1" address="&#x24;72FA0000" size="65536"/>
<load_dll dll="C:\WINDOWS\system32\WZCSvc.DLL" successful="1" address="&#x24;775F0000" size="450560"/>
<load_dll dll="C:\WINDOWS\system32\WMI.dll" successful="1" address="&#x24;76CF0000" size="16384"/>
<load_dll dll="C:\WINDOWS\system32\DHCPCSVC.DLL" successful="1" address="&#x24;76D40000" size="122880"/>
<load_dll dll="C:\WINDOWS\system32\ESENT.dll" successful="1" address="&#x24;5E200000" size="1114112"/>
<load_dll dll="C:\WINDOWS\system32\wzcdlg.dll" successful="1" address="&#x24;4F4A0000" size="389120"/>
<load_dll dll="C:\WINDOWS\system32\WINHTTP.dll" successful="1" address="&#x24;4D5C0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1" address="&#x24;5E490000" size="53248"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1" address="&#x24;590B0000" size="28672"/>
</dll_handling_section>
</process>
</processes>
</analysis>
