<?xml version="1.0"?>
<!-- This analysis was created by CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="1.107" time="19.04.2007 18:55:20" file="f13e346d522ee3b4d6a96cea37dfd0f5.exe" logpath="C:\analysis\log\f13e346d522ee3b4d6a96cea37dfd0f5.exe\run_1\">
<calltree>
<process_call index="1" pid="584" filename="c:\f13e346d522ee3b4d6a96cea37dfd0f5.exe" starttime="00:00.250" startreason="AnalysisTarget"/>
</calltree>

<processes>
<process index="1" pid="584" filename="c:\f13e346d522ee3b4d6a96cea37dfd0f5.exe" filesize="24576" md5="f13e346d522ee3b4d6a96cea37dfd0f5" username="nepenthes" parentindex="0" starttime="00:00.250" terminationtime="00:04.985" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="3130">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="31919">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.10-36" signature_file_version="6.38.1.13">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\f13e346d522ee3b4d6a96cea37dfd0f5.exe" successful="1" address="&#x24;400000" size="24576"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1" address="&#x24;77D10000" size="589824"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1" address="&#x24;77EF0000" size="290816"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1" address="&#x24;77E50000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1" address="&#x24;770F0000" size="573440"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1" address="&#x24;77BE0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1" address="&#x24;5D450000" size="630784"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1" address="&#x24;71A30000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1" address="&#x24;71A10000" size="94208"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1" address="&#x24;71A00000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1" address="&#x24;5E490000" size="53248"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1" address="&#x24;76AD0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1" address="&#x24;590B0000" size="28672"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
<load_dll dll="ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="advapi32.dll" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="comctl32.dll" successful="1" address="&#x24;773A0000" size="1060864"/>
<load_dll dll="Comctl32.dll" successful="1" address="&#x24;773A0000" size="1060864"/>
<load_dll dll="RichEd20.dll" successful="1" address="&#x24;74DB0000" size="442368"/>
<load_dll dll="mshtml.dll" successful="1" address="&#x24;7DBE0000" size="3100672"/>
</dll_handling_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\CurrentControlSet\Services\crypt32\Performance"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1"/>
</registry_section>
<process_section>
<kill_process targetpid="584" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
</process>
</processes>
</analysis>
