<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
  <report_version>
	  <major>3</major>
		<minor>1</minor>
	</report_version>
	<configuration>
	  <time_needed>28 s</time_needed>
		<report_created>01/13/11, 15:48:34 UTC</report_created>
		<termination_reason>All tracked processes have exited</termination_reason>
		<ttanalyze_version>
		  <prog_version>1.74.3195</prog_version>
			<svn_revision>$Revision: 3195 $</svn_revision>
			<build_date>Sep 24 2010 16:09:28</build_date>
		</ttanalyze_version>
	</configuration>
	<summary>
	  <auto_start>false</auto_start>
		<internet_settings>false</internet_settings>
		<bho>false</bho>
		<win_dir_copy>true</win_dir_copy>
		<av_kill>false</av_kill>
		<com_object>false</com_object>
		<dlf>false</dlf>
		<ircbot>false</ircbot>
		<spambot>false</spambot>
		<addressscan>false</addressscan>
		<portscan>false</portscan>
		<file_modification_destruction>true</file_modification_destruction>
		<process_spawn>false</process_spawn>
		<all_reg_activities>true</all_reg_activities>
		<severity_level>2</severity_level>
	</summary>
	<analysis_subject>
	  <general>
		  <id>2</id>
			<parent_id>1</parent_id>
			<analysis_reason>Primary Analysis Subject</analysis_reason>
			<submission_fn>39792098</submission_fn>
			<virtual_fn>39792098.exe</virtual_fn>
			<virtual_path>C:\39792098.exe</virtual_path>
			<arguments>"C:\39792098.exe" </arguments>
			<status>dead</status>
			<exit_code>-1073741819</exit_code>
			<md5>aad02b0475e73730bca416a115c2a16c</md5>
			<sha1>fab0cfbfbe0efec30f67356c02baf671e4eeb2e2</sha1>
			<file_size>460288</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77B40000" base_name="Apphelp.dll" full_name="C:\WINDOWS\system32\Apphelp.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_read count="1" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="AuthenticodeEnabled"/>
				<reg_value_read count="2" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSUserEnabled"/>
			</registry_activities>
			<file_activities>
			  <file_created name="C:\39792098 .exe"/>
				<file_created name="C:\WINDOWS\System32\geedc.dll"/>
				<file_modified description="file_modification_destruction" name="C:\39792098 .exe"/>
				<file_modified description="file_modification_destruction" name="C:\WINDOWS\System32\geedc.dll"/>
				<section_object_created file_name="C:\39792098 .exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\System32\geedc.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
			</file_activities>
			<misc_activities>
			  <exception_occurred count="1" description="Exception 0xc0000096 (STATUS_PRIVILEGED_INSTRUCTION) at 0x100021f3"/>
				<exception_occurred count="1" description="Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x10001666"/>
				<exception_occurred count="1" description="Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x10"/>
			</misc_activities>
		</activities>
		<sigbuster>PE_Compact v1.68-1.84 SN:709
PE_Compact v1.40-v1.45 SN:1265</sigbuster>
		<ikarus_scanner>
		  <sig id="1393623" name="P2P-Worm.Win32.Palevo"/>
		</ikarus_scanner>
	</analysis_subject>
	<global_file_info>
	  <global_file info="PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit" md5="48d1a9ab2f2bfc855383a7696c5fab35" mimetype="application/x-dosexec" name="geedc.dll" sha1="841c6f87c384311c821bd76f848b47c5498fb1b4"/>
		<global_file info="MS-DOS executable, MZ for MS-DOS" md5="cb032b12af742555e60124f6d7d2d2ea" mimetype="application/x-dosexec" name="39792098 .exe" sha1="692003e15150403fa919d83ba2cefcf217b9e2e2"/>
	</global_file_info>
</analysis>
