<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
  <report_version>
	  <major>3</major>
		<minor>2</minor>
	</report_version>
	<configuration>
	  <time_needed>255 s</time_needed>
		<report_created>04/22/11, 04:48:16 UTC</report_created>
		<termination_reason>Timeout</termination_reason>
		<ttanalyze_version>
		  <prog_version>1.75.3394</prog_version>
			<svn_revision>$Revision: 3603 $</svn_revision>
			<build_date>Feb 24 2011 16:24:07</build_date>
		</ttanalyze_version>
	</configuration>
	<summary>
	  <auto_start>false</auto_start>
		<internet_settings>false</internet_settings>
		<bho>false</bho>
		<win_dir_copy>false</win_dir_copy>
		<av_kill>false</av_kill>
		<com_object>false</com_object>
		<dlf>false</dlf>
		<ircbot>false</ircbot>
		<spambot>false</spambot>
		<addressscan>false</addressscan>
		<portscan>false</portscan>
		<file_modification_destruction>false</file_modification_destruction>
		<process_spawn>false</process_spawn>
		<all_reg_activities>true</all_reg_activities>
		<write_to_foreign_mem_area>false</write_to_foreign_mem_area>
		<install_service>false</install_service>
		<load_driver>false</load_driver>
		<install_ie_toolbar>false</install_ie_toolbar>
		<disable_win_update>false</disable_win_update>
		<change_win_firewall_settings>false</change_win_firewall_settings>
		<harvesting_emails>false</harvesting_emails>
		<mod_sys_files>false</mod_sys_files>
		<modify_files_only_in_user_dir>false</modify_files_only_in_user_dir>
		<packed_binary>false</packed_binary>
		<av_hit>true</av_hit>
		<crash>false</crash>
		<autorun>false</autorun>
		<severity_level>0</severity_level>
	</summary>
	<analysis_subject>
	  <general>
		  <id>2</id>
			<parent_id>1</parent_id>
			<analysis_reason>Primary Analysis Subject</analysis_reason>
			<submission_fn>46103314</submission_fn>
			<virtual_fn>46103314.exe</virtual_fn>
			<virtual_path>C:\46103314.exe</virtual_path>
			<arguments>"C:\46103314.exe"</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>8c2dd2c861cb4998e852c061c7c197db</md5>
			<sha1>a60c897620d32d212a125b2e1694a0a4b20a143e</sha1>
			<file_size>95232</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x7E410000" base_name="user32.dll" full_name="C:\WINDOWS\system32\user32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x77DD0000" base_name="advapi32.dll" full_name="C:\WINDOWS\system32\advapi32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77120000" base_name="oleaut32.dll" full_name="C:\WINDOWS\system32\oleaut32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x5ED00000" base_name="opengl32.dll" full_name="C:\WINDOWS\system32\opengl32.dll" is_load_time_dependency="1" load_time="1" size="0x000CC000"/>
			<loaded_dll base_address="0x68B20000" base_name="GLU32.dll" full_name="C:\WINDOWS\system32\GLU32.dll" is_load_time_dependency="1" load_time="1" size="0x00020000"/>
			<loaded_dll base_address="0x73760000" base_name="DDRAW.dll" full_name="C:\WINDOWS\system32\DDRAW.dll" is_load_time_dependency="1" load_time="1" size="0x0004B000"/>
			<loaded_dll base_address="0x73BC0000" base_name="DCIMAN32.dll" full_name="C:\WINDOWS\system32\DCIMAN32.dll" is_load_time_dependency="1" load_time="1" size="0x00006000"/>
			<loaded_dll base_address="0x76B40000" base_name="winmm.dll" full_name="C:\WINDOWS\system32\winmm.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKLM\Software\Microsoft\DirectDraw\MostRecentApplication" value_data="3406304190" value_name="ID"/>
				<reg_value_modified count="1" key="HKLM\Software\Microsoft\DirectDraw\MostRecentApplication" value_data="46103314.exe" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Bug!" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Bug!" value_data="0x3d620932" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Bug!" value_data="BUG!.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\DemolitionDerby2" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\DemolitionDerby2" value_data="0x44838832" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\DemolitionDerby2" value_data="DD2.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MortalKombat3" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MortalKombat3" value_data="0xfc6de731" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MortalKombat3" value_data="MK3W.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MsGolf98" value_data="0x20000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MsGolf98" value_data="0x0dea1a35" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\MsGolf98" value_data="game.exe" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NHLPowerPlay" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NHLPowerPlay" value_data="0xff3fbf31" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NHLPowerPlay" value_data="PP96.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NortonSystemInfo" value_data="0x04000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NortonSystemInfo" value_data="0x29ea6332" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\NortonSystemInfo" value_data="SI32.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Rogue Squadron" value_data="0x40000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Rogue Squadron" value_data="0xd1d74c36" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Rogue Squadron" value_data="ROGUE SQUADRON.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Savage" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Savage" value_data="0x00876531" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Savage" value_data="SAVAGE32.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ScorchedPlanet" value_data="0x02000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ScorchedPlanet" value_data="0x69044c32" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ScorchedPlanet" value_data="SPLANETW.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\SilentThunder" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\SilentThunder" value_data="] 5V" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\SilentThunder" value_data="A10SIM.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Terracide" value_data="0x04000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Terracide" value_data="0x66cb9533" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\Terracide" value_data="TERAWIN.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ThirdDimension" value_data="0x04000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ThirdDimension" value_data="0xbf817f32" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ThirdDimension" value_data="t3rd.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisQualityBenchmark" value_data="0x04000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisQualityBenchmark" value_data="m[M3" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisQualityBenchmark" value_data="BEND3DIM.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisWinMarkBenchmark" value_data="0x04000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisWinMarkBenchmark" value_data="0x46fc4b33" value_name="ID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\DirectDraw\Compatibility\ZiffDavisWinMarkBenchmark" value_data="WBD3D.EXE" value_name="Name"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm" value_data="1" value_name="wheel"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSUserEnabled"/>
			</registry_activities>
			<file_activities>
			  <file_read name="C:\46103314.exe"/>
				<file_read name="C:\WINDOWS\win.ini"/>
				<section_object_created file_name="C:\WINDOWS\system32\DCIMAN32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\DDRAW.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\GLU32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\opengl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\winmm.dll" section_name=""/>
				<fs_control_communication control_code="0x00090028" count="1" file="C:\Program Files\Common Files\"/>
				<device_control_communication control_code="0x00390008" count="8" file="\Device\KsecDD"/>
			</file_activities>
			<misc_activities>
			  <mutex_created name="DDrawDriverObjectListMutex"/>
				<mutex_created name="DDrawWindowListMutex"/>
				<mutex_created name="__DDrawCheckExclMode__"/>
				<mutex_created name="__DDrawExclMode__"/>
				<exception_occurred count="57" description="Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x76b42aca"/>
			</misc_activities>
		</activities>
		<ikarus_scanner>
		  <sig id="1438715" name="Worm.Win32.Rimecud"/>
		</ikarus_scanner>
	</analysis_subject>
	<global_file_info/>
</analysis>
