<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
 <report_version>
  <major>3</major>
  <minor>1</minor>
 </report_version>
 <configuration>
  <time_needed>240 s</time_needed>
  <report_created>03/25/09, 21:19:40 UTC</report_created>
  <termination_reason>Timeout</termination_reason>
  <ttanalyze_version>
   <prog_version>1.67.0</prog_version>
   <svn_revision>$Revision: 1558 $</svn_revision>
   <build_date>Dec 22 2008 16:54:40</build_date>
  </ttanalyze_version>
 </configuration>
 <summary>
  <auto_start>false</auto_start>
  <internet_settings>false</internet_settings>
  <bho>false</bho>
  <win_dir_copy>true</win_dir_copy>
  <av_kill>false</av_kill>
  <com_object>false</com_object>
  <dlf>false</dlf>
  <ircbot>false</ircbot>
  <spambot>false</spambot>
  <addressscan>false</addressscan>
  <portscan>false</portscan>
  <file_modification_destruction>true</file_modification_destruction>
  <process_spawn>true</process_spawn>
  <all_reg_activities>true</all_reg_activities>
  <severity_level>2</severity_level>
 </summary>
 <analysis_subject>
  <general>
   <id>2</id>
   <parent_id>1</parent_id>
   <analysis_reason>Primary Analysis Subject</analysis_reason>
   <submission_fn>important.exe</submission_fn>
   <virtual_fn>sample.exe</virtual_fn>
   <virtual_path>C:\sample.exe</virtual_path>
   <arguments>"C:\sample.exe"</arguments>
   <status>dead</status>
   <exit_code>0</exit_code>
   <md5>83b4560333601224cb0d5709bdf57191</md5>
   <sha1>d058f905b1283744ee6b7ed5be42fc861b4788cc</sha1>
   <file_size>135168</file_size>
  </general>
  <dll_dependencies>
   <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
   <loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
   <loaded_dll base_address="0x7E410000" base_name="user32.dll" full_name="C:\WINDOWS\system32\user32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
   <loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
   <loaded_dll base_address="0x77DD0000" base_name="advapi32.dll" full_name="C:\WINDOWS\system32\advapi32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
   <loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
   <loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
   <loaded_dll base_address="0x76390000" base_name="IMM32.DLL" full_name="C:\WINDOWS\system32\IMM32.DLL" is_load_time_dependency="1" load_time="1" size="0x0001D000"/>
   <loaded_dll base_address="0x77B40000" base_name="Apphelp.dll" full_name="C:\WINDOWS\system32\Apphelp.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
  </dll_dependencies>
  <activities>
   <registry_activities>
    <reg_value_read count="1" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="AuthenticodeEnabled"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="262144" value_name="DefaultLevel"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="PolicyScope"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="32771" value_name="HashAlg"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0x5eab304f957a49896a006c1c31154015" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="779" value_name="ItemSize"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="32771" value_name="HashAlg"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0x67b0d48b343a3fd3bce9dc646704f394" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="517" value_name="ItemSize"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="32771" value_name="HashAlg"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0x327802dcfef8c893dc8ab006dd847d1d" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="918" value_name="ItemSize"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="32771" value_name="HashAlg"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0xbd9a2adb42ebd8560e250e4df8162f67" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="229" value_name="ItemSize"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="32771" value_name="HashAlg"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0x386b085f84ecf669d36b956a22c01e80" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="370" value_name="ItemSize"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK*" value_name="ItemData"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="0" value_name="SaferFlags"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Local Settings\Temporary Internet Files" value_name="Cache"/>
   </registry_activities>
   <file_activities>
    <file_created name="C:\WINDOWS\system32\bho32.exe"/>
    <file_modified description="file_modification_destruction" name="C:\WINDOWS\system32\bho32.exe"/>
    <section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\bho32.exe" section_name=""/>
    <section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
   </file_activities>
   <process_activities>
    <remote_thread_created process="C:\WINDOWS\system32\bho32.exe"/>
    <foreign_mem_area_read process="C:\WINDOWS\system32\bho32.exe"/>
    <foreign_mem_area_write process="C:\WINDOWS\system32\bho32.exe"/>
    <process_created cmd_line="" description="process_spawn" exe_name="C:\WINDOWS\system32\bho32.exe"/>
   </process_activities>
  </activities>
  <ikarus_scanner>
   <sig id="26741327" name="Trojan.Win32.Tibs"/>
  </ikarus_scanner>
 </analysis_subject>
 <analysis_subject>
  <general>
   <id>3</id>
   <parent_id>2</parent_id>
   <analysis_reason>Started by sample.exe</analysis_reason>
   <virtual_fn>bho32.exe</virtual_fn>
   <virtual_path>C:\WINDOWS\system32\bho32.exe</virtual_path>
   <arguments>C:\WINDOWS\system32\bho32.exe</arguments>
   <status>alive</status>
   <exit_code>0</exit_code>
   <md5>8aeee66c5c8bf753e8cf1dc6a7ca135d</md5>
   <sha1>27f91dbef2bc9627b04caaa70e195e79720feb61</sha1>
   <file_size>117776</file_size>
  </general>
  <dll_dependencies>
   <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
   <loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
   <loaded_dll base_address="0x003D0000" base_name="Normaliz.dll" full_name="C:\WINDOWS\system32\Normaliz.dll" is_load_time_dependency="0" load_time="2" size="0x00009000"/>
   <loaded_dll base_address="0x42990000" base_name="iertutil.dll" full_name="C:\WINDOWS\system32\iertutil.dll" is_load_time_dependency="0" load_time="2" size="0x00045000"/>
   <loaded_dll base_address="0x42C10000" base_name="wininet.dll" full_name="C:\WINDOWS\system32\wininet.dll" is_load_time_dependency="0" load_time="2" size="0x000CF000"/>
   <loaded_dll base_address="0x5B860000" base_name="netapi32.dll" full_name="C:\WINDOWS\system32\netapi32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
   <loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="0" load_time="2" size="0x0009A000"/>
   <loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="0" load_time="2" size="0x0004C000"/>
   <loaded_dll base_address="0x755C0000" base_name="msctfime.ime" full_name="C:\WINDOWS\system32\msctfime.ime" is_load_time_dependency="0" load_time="2" size="0x0002E000"/>
   <loaded_dll base_address="0x76390000" base_name="IMM32.DLL" full_name="C:\WINDOWS\system32\IMM32.DLL" is_load_time_dependency="0" load_time="2" size="0x0001D000"/>
   <loaded_dll base_address="0x77120000" base_name="oleaut32.dll" full_name="C:\WINDOWS\system32\oleaut32.dll" is_load_time_dependency="0" load_time="2" size="0x0008B000"/>
   <loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="0" load_time="2" size="0x00103000"/>
   <loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="0" load_time="2" size="0x0013D000"/>
   <loaded_dll base_address="0x77C00000" base_name="version.dll" full_name="C:\WINDOWS\system32\version.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
   <loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="0" load_time="2" size="0x00058000"/>
   <loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x0009B000"/>
   <loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="0" load_time="2" size="0x00092000"/>
   <loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="0" load_time="2" size="0x00049000"/>
   <loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00076000"/>
   <loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="0" load_time="2" size="0x00011000"/>
   <loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="0" load_time="2" size="0x00817000"/>
   <loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="0" load_time="2" size="0x00091000"/>
  </dll_dependencies>
  <activities>
   <registry_activities>
    <reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\CTF\SystemShared\" value_data="0" value_name="CUAS"/>
    <reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
    <reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\CTF\SystemShared" value_data="0" value_name="CUAS"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM" value_data="msctfime.ime" value_name="Ime File"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" value_data="" value_name="AppInit_DLLs"/>
    <reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSAppCompat"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSUserEnabled"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Application Data" value_name="AppData"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Cookies" value_name="Cookies"/>
   </registry_activities>
   <file_activities>
    <file_modified description="file_modification_destruction" name="WMIDataDevice"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@2o7[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@ad.yieldmanager[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@adobe[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@adopt.euroclick[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@adopt.specificclick[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@adrevolver[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@ads.revsci[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@advertising[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@amazon[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@apmebf[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@ar.voicefive[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@atdmt[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@atwola[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@burstnet[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@c.msn[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@c1.microsoft[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@casalemedia[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@com[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@contextweb[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@download[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@ehg-verizon.hitbox[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@fastclick[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@google[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@google[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@hitbox[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@icq[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@iseclab[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@live365[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@live[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@m.webtrends[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@media.adrevolver[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@mediaplex[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@microsoft[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@microsoftwga.112.2o7[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@msn[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@msnportal.112.2o7[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@news[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@onlinestores.metaservices.microsoft[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@planetpdf[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@questionmarket[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@rad.msn[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@realmedia[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@revsci[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@search.live[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@search.microsoft[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@support.microsoft[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@symantec[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@tacoda[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@update.microsoft[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@verizon[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@voicefive[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@westernunion[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@www.microsoft[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@www.msn[2].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@www22.verizon[1].txt"/>
    <file_read name="C:\Documents and Settings\user\Cookies\user@zedo[1].txt"/>
    <section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\IMM32.DLL" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\MSCTF.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\msctfime.ime" section_name=""/>
    <device_control_communication control_code="0x00390008" count="1" file="\Device\KsecDD"/>
    <device_control_communication control_code="0x0022414C" count="2" file="WMIDataDevice"/>
    <device_control_communication control_code="0x00228144" count="2" file="WMIDataDevice"/>
   </file_activities>
   <process_activities>
    <thread_information>
     <thread_status number_of_threads="1" time="145"/>
    </thread_information>
   </process_activities>
  </activities>
  <ikarus_scanner>
   <sig id="234560" name="Trojan.Zlob"/>
  </ikarus_scanner>
 </analysis_subject>
</analysis>
