<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
 <report_version>
  <major>3</major>
  <minor>0</minor>
 </report_version>
 <configuration>
  <time_needed>241 s</time_needed>
  <report_created>08/20/08, 03:24:32</report_created>
  <termination_reason>Timeout</termination_reason>
  <ttanalyze_version>
   <prog_version>1.62.0</prog_version>
   <svn_revision>$Revision: 645 $</svn_revision>
   <build_date>Jun  5 2008 17:10:39</build_date>
  </ttanalyze_version>
 </configuration>
 <summary>
  <auto_start>false</auto_start>
  <internet_settings>false</internet_settings>
  <bho>false</bho>
  <win_dir_copy>false</win_dir_copy>
  <av_kill>false</av_kill>
  <com_object>false</com_object>
  <dlf>false</dlf>
  <ircbot>false</ircbot>
  <spambot>false</spambot>
  <addressscan>false</addressscan>
  <portscan>false</portscan>
 </summary>
 <analysis_subject>
  <general>
   <id>2</id>
   <parent_id>1</parent_id>
   <analysis_reason>Primary Analysis Subject</analysis_reason>
   <virtual_fn>sample.exe</virtual_fn>
   <virtual_path>C:\sample.exe</virtual_path>
   <arguments>"C:\sample.exe"</arguments>
   <status>alive</status>
   <exit_code>0</exit_code>
   <md5>e276f2c49d194def764a383482ecbd03</md5>
   <sha1>e6809cd336e4065bf1db62c6ea24fa064ef9ac84</sha1>
   <file_size>7680</file_size>
  </general>
  <dll_dependencies>
   <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
   <loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
   <loaded_dll base_address="0x7E410000" base_name="user32.dll" full_name="C:\WINDOWS\system32\user32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
   <loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
   <loaded_dll base_address="0x77DD0000" base_name="advapi32.dll" full_name="C:\WINDOWS\system32\advapi32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
   <loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
   <loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
   <loaded_dll base_address="0x76390000" base_name="IMM32.DLL" full_name="C:\WINDOWS\system32\IMM32.DLL" is_load_time_dependency="1" load_time="1" size="0x0001D000"/>
  </dll_dependencies>
  <activities>
   <registry_activities>
    <reg_value_modified count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\INPROCSERVER32" value_data="C:\DOCUME~1\user\LOCALS~1\Temp\\shell32.dll" value_name=""/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="USER" value_name="ComputerName"/>
   </registry_activities>
   <file_activities>
    <file_created name="C:\DOCUME~1\user\LOCALS~1\Temp\123.info"/>
    <file_created name="C:\DOCUME~1\user\LOCALS~1\Temp\shell32.dll"/>
    <file_modified name="PIPE\lsarpc"/>
    <file_read name="C:\sample.exe"/>
    <file_read name="PIPE\lsarpc"/>
    <fs_control_communication control_code="0x0011C017" count="3" file="PIPE\lsarpc"/>
   </file_activities>
  </activities>
  <ikarus_scanner>
   <sig id="272649" name="Virus.Trojan.Win32.Inject.dnz"/>
  </ikarus_scanner>
 </analysis_subject>
</analysis>
