Código:
Executing: c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe
LoadLibrary(kernel32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(user32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(advapi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(oleaut32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(msvcrt.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(ole32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(version.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(gdi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(wininet.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(shlwapi.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(normaliz.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(urlmon.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(iertutil.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(comctl32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(kernel32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
VirtualQueryEx(c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(Kernel32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcessToken(C:\Documents and Settings\r32\Escritorio\Infect3d\Comprovante\Projeto.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
ResumeThread() [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(Advapi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(LPK.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(Projeto.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(USER32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(imm32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(oleaut32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(USER32.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(comctl32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
IsDebuggerPresent() [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
FreeLibrary(C:\WINDOWS\system32\uxtheme.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
BitBlt() [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(version.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
FreeLibrary() [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenMutex(ShimCacheMutex) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(dbghelp.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(SbieDll.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(wsock32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(ws2_32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(ws2help.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(shell32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateEvent(ShellCopyEngineRunning) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(EXPLORER.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(setupapi.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(rpcrt4.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetComputerName() [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
AdjustTokenPrivileges(SE_PRIVILEGE_ENABLED) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateEvent(ShellCopyEngineFinished) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
CreateProcess((null),C:\WINDOWS\winsa64.exe,C:\WINDOWS) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(winlogon.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(advapi32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(c:\windows\system32\apphelp.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
FreeLibrary(C:\WINDOWS\system32\ADVAPI32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
WriteProcessMemory(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_READWRITE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
ExitProcess(0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(C:\WINDOWS\system32\Msctf.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(ctfmon.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(SbieCtrl.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(explorer.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
Executing: c:\windows\winsa64.exe
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,103000,PAGE_READWRITE) [c:\windows\winsa64.exe]
OpenProcess(wireshark.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(u1210.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(sniff_hit.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(VBoxTray.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(procexp.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(kernel32.dll) [c:\windows\winsa64.exe]
LoadLibrary(user32.dll) [c:\windows\winsa64.exe]
LoadLibrary(advapi32.dll) [c:\windows\winsa64.exe]
LoadLibrary(oleaut32.dll) [c:\windows\winsa64.exe]
LoadLibrary(msvcrt.dll) [c:\windows\winsa64.exe]
LoadLibrary(ole32.dll) [c:\windows\winsa64.exe]
LoadLibrary(version.dll) [c:\windows\winsa64.exe]
OpenProcess(BSA.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(gdi32.dll) [c:\windows\winsa64.exe]
LoadLibrary(wininet.dll) [c:\windows\winsa64.exe]
LoadLibrary(shlwapi.dll) [c:\windows\winsa64.exe]
LoadLibrary(normaliz.dll) [c:\windows\winsa64.exe]
LoadLibrary(urlmon.dll) [c:\windows\winsa64.exe]
LoadLibrary(iertutil.dll) [c:\windows\winsa64.exe]
LoadLibrary(comctl32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(lz32.dll) [c:\windows\winsa64.exe]
LoadLibrary(lz32.dll) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_READWRITE) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_READWRITE) [c:\windows\winsa64.exe]
GetModuleHandle(kernel32.dll) [c:\windows\winsa64.exe]
VirtualQueryEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe) [c:\windows\winsa64.exe]
GetModuleHandle(Kernel32) [c:\windows\winsa64.exe]
OpenProcess(dumpcap.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\windows\winsa64.exe]
OpenProcessToken(C:\WINDOWS\winsa64.exe) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\windows\winsa64.exe]
OpenProcess(jsobs.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
ResumeThread() [c:\windows\winsa64.exe]
OpenProcess(PE Explorer (portable).exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(idag.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
GetModuleHandle(Advapi32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(LPK.DLL) [c:\windows\winsa64.exe]
OpenProcess(winsa64.exe) [c:\windows\winsa64.exe]
GetModuleHandle(USER32) [c:\windows\winsa64.exe]
LoadLibrary(imm32.dll) [c:\windows\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\windows\winsa64.exe]
OpenProcess(notepad.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
OpenProcess(EvO_DBG.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_NOACCESS) [c:\windows\winsa64.exe]
GetModuleHandle(oleaut32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(USER32.DLL) [c:\windows\winsa64.exe]
GetModuleHandle(comctl32.dll) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\windows\winsa64.exe]
IsDebuggerPresent() [c:\windows\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\uxtheme.dll) [c:\windows\winsa64.exe]
BitBlt() [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,0) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_EXECUTE_READWRITE) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\windows\winsa64.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\windows\winsa64.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
GetModuleHandle(version.dll) [c:\windows\winsa64.exe]
FreeLibrary() [c:\windows\winsa64.exe]
OpenMutex(ShimCacheMutex) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [c:\windows\winsa64.exe]
GetModuleHandle(dbghelp.dll) [c:\windows\winsa64.exe]
GetModuleHandle(SbieDll.dll) [c:\windows\winsa64.exe]
LoadLibrary(wsock32.dll) [c:\windows\winsa64.exe]
LoadLibrary(ws2_32.dll) [c:\windows\winsa64.exe]
LoadLibrary(ws2help.dll) [c:\windows\winsa64.exe]
LoadLibrary(shell32.dll) [c:\windows\winsa64.exe]
CreateMutex(INSONIA) [c:\windows\winsa64.exe]
CreateFile(C:\WINDOWS\winsa64.cfg) [c:\windows\winsa64.exe]
Sleep(100) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\mswsock.dll) [c:\windows\winsa64.exe]
LoadLibrary(hnetcfg.dll) [c:\windows\winsa64.exe]
LoadLibrary(rpcrt4.dll) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\wshtcpip.dll) [c:\windows\winsa64.exe]
LoadLibrary(dnsapi.dll) [c:\windows\winsa64.exe]
LoadLibrary(iphlpapi.dll) [c:\windows\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\IMM32.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\projeto.exe]
LoadLibrary(c:\windows\system32\winrnr.dll) [c:\windows\winsa64.exe]
LoadLibrary(wldap32.dll) [c:\windows\winsa64.exe]
LoadLibrary(rasadhlp.dll) [c:\windows\winsa64.exe]
GetModuleHandle(ws2_32.dll) [c:\windows\winsa64.exe]
connect( 212.1.208.24:80 ) [c:\windows\winsa64.exe]
DeleteFile(C:\WINDOWS\a.exe) [c:\windows\winsa64.exe]
Sleep(60000000) [c:\windows\winsa64.exe]
Descarga dos archivos, "winsa64.exe" y el archivo "winsa64.cfg" que contiene el dominio no-ip asociado:

Análisis del archivo "winsa64.exe" (Api Log):
Código:
Executing: c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe
LoadLibrary(kernel32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(user32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(advapi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(oleaut32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(msvcrt.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(ole32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(version.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(gdi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(wininet.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(shlwapi.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(normaliz.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(urlmon.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(iertutil.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(comctl32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(kernel32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
VirtualQueryEx(c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(Kernel32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcessToken(C:\Documents and Settings\r32\Escritorio\Infect3d\Comprovante\winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
ResumeThread() [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(Advapi32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(LPK.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(USER32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(imm32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(oleaut32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(USER32.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(comctl32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
IsDebuggerPresent() [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\uxtheme.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
BitBlt() [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(version.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
FreeLibrary() [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenMutex(ShimCacheMutex) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(dbghelp.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(SbieDll.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(wsock32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(ws2_32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(ws2help.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(shell32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateEvent(ShellCopyEngineRunning) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(EXPLORER.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(setupapi.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(rpcrt4.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetComputerName() [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
AdjustTokenPrivileges(SE_PRIVILEGE_ENABLED) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateEvent(ShellCopyEngineFinished) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateProcess((null),C:\WINDOWS\winsa64.exe,C:\WINDOWS) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(winlogon.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(advapi32) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\ADVAPI32.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
WriteProcessMemory(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_READWRITE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
ExitProcess(0) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\Msctf.dll) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(ctfmon.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(explorer.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(u1210.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
Executing: c:\windows\winsa64.exe
OpenProcess(wireshark.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(sniff_hit.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,103000,PAGE_READWRITE) [c:\windows\winsa64.exe]
OpenProcess(SbieCtrl.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(iexplore.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(firefox.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(VBoxTray.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(procexp.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
OpenProcess(BSA.EXE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
LoadLibrary(kernel32.dll) [c:\windows\winsa64.exe]
LoadLibrary(user32.dll) [c:\windows\winsa64.exe]
LoadLibrary(advapi32.dll) [c:\windows\winsa64.exe]
LoadLibrary(oleaut32.dll) [c:\windows\winsa64.exe]
LoadLibrary(msvcrt.dll) [c:\windows\winsa64.exe]
LoadLibrary(ole32.dll) [c:\windows\winsa64.exe]
LoadLibrary(version.dll) [c:\windows\winsa64.exe]
LoadLibrary(gdi32.dll) [c:\windows\winsa64.exe]
LoadLibrary(wininet.dll) [c:\windows\winsa64.exe]
LoadLibrary(shlwapi.dll) [c:\windows\winsa64.exe]
LoadLibrary(normaliz.dll) [c:\windows\winsa64.exe]
LoadLibrary(urlmon.dll) [c:\windows\winsa64.exe]
LoadLibrary(iertutil.dll) [c:\windows\winsa64.exe]
LoadLibrary(comctl32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(lz32.dll) [c:\windows\winsa64.exe]
LoadLibrary(lz32.dll) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_READWRITE) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_READWRITE) [c:\windows\winsa64.exe]
GetModuleHandle(kernel32.dll) [c:\windows\winsa64.exe]
VirtualQueryEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe) [c:\windows\winsa64.exe]
OpenProcess(XueTr.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
GetModuleHandle(Kernel32) [c:\windows\winsa64.exe]
OpenProcess(dumpcap.exe) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\windows\winsa64.exe]
OpenProcessToken(C:\WINDOWS\winsa64.exe) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\windows\winsa64.exe]
ResumeThread() [c:\windows\winsa64.exe]
GetModuleHandle(Advapi32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(LPK.DLL) [c:\windows\winsa64.exe]
OpenProcess(winsa64.exe) [c:\windows\winsa64.exe]
GetModuleHandle(USER32) [c:\windows\winsa64.exe]
LoadLibrary(imm32.dll) [c:\windows\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_RESERVE,PAGE_NOACCESS) [c:\windows\winsa64.exe]
GetModuleHandle(oleaut32.dll) [c:\windows\winsa64.exe]
GetModuleHandle(USER32.DLL) [c:\windows\winsa64.exe]
GetModuleHandle(comctl32.dll) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\windows\winsa64.exe]
IsDebuggerPresent() [c:\windows\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\uxtheme.dll) [c:\windows\winsa64.exe]
BitBlt() [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\windows\winsa64.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,0) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\sandbox\r32\defaultbox\drive\c\windows\winsa64.exe,MEM_COMMIT,PAGE_EXECUTE_READWRITE) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\windows\winsa64.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\windows\winsa64.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\winsa64.exe]
GetModuleHandle(version.dll) [c:\windows\winsa64.exe]
FreeLibrary() [c:\windows\winsa64.exe]
OpenMutex(ShimCacheMutex) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [c:\windows\winsa64.exe]
GetModuleHandle(dbghelp.dll) [c:\windows\winsa64.exe]
GetModuleHandle(SbieDll.dll) [c:\windows\winsa64.exe]
LoadLibrary(wsock32.dll) [c:\windows\winsa64.exe]
LoadLibrary(ws2_32.dll) [c:\windows\winsa64.exe]
LoadLibrary(ws2help.dll) [c:\windows\winsa64.exe]
LoadLibrary(shell32.dll) [c:\windows\winsa64.exe]
VirtualAllocEx(c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
FreeLibrary(C:\WINDOWS\system32\IMM32.DLL) [c:\documents and settings\r32\escritorio\infect3d\comprovante\winsa64.exe]
CreateMutex(INSONIA) [c:\windows\winsa64.exe]
CreateFile(C:\WINDOWS\winsa64.cfg) [c:\windows\winsa64.exe]
Sleep(100) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\mswsock.dll) [c:\windows\winsa64.exe]
LoadLibrary(hnetcfg.dll) [c:\windows\winsa64.exe]
LoadLibrary(rpcrt4.dll) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\wshtcpip.dll) [c:\windows\winsa64.exe]
LoadLibrary(dnsapi.dll) [c:\windows\winsa64.exe]
LoadLibrary(iphlpapi.dll) [c:\windows\winsa64.exe]
LoadLibrary(c:\windows\system32\winrnr.dll) [c:\windows\winsa64.exe]
LoadLibrary(wldap32.dll) [c:\windows\winsa64.exe]
LoadLibrary(rasadhlp.dll) [c:\windows\winsa64.exe]
GetModuleHandle(ws2_32.dll) [c:\windows\winsa64.exe]
connect( 212.1.208.24:80 ) [c:\windows\winsa64.exe]
DeleteFile(C:\WINDOWS\a.exe) [c:\windows\winsa64.exe]
Sleep(60000000) [c:\windows\winsa64.exe]
Executing: c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe
LoadLibrary(kernel32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(user32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(advapi32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(oleaut32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(msvcrt.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(ole32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(version.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(gdi32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(comctl32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(shlwapi.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(shell32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(wininet.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(normaliz.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(urlmon.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(iertutil.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(imm32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(winspool.drv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(comdlg32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(winmm.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(lz32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(lz32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(kernel32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
VirtualQueryEx(c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(Kernel32) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenProcessToken(C:\Documents and Settings\r32\Mis documentos\Tools\HxD\HxD.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(LPK.DLL) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
ResumeThread() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(Advapi32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateEvent(DINPUTWINMM) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FindWindow(STATIC,000003C4_PID_FastMM) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
IsDebuggerPresent() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\uxtheme.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(version.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenMutex(ShimCacheMutex) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(oleaut32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(USER32.DLL) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
BitBlt() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\Documents and Settings\r32\Mis documentos\Tools\HxD\HxD.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(USER32) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(ole32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(psapi.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(comctl32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(msimg32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETMENUANIMATION,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FindWindow(TXmInstanceManager,HxD{73025671-91B6-473C-B0EE-6EAB6FD0E6DE}) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(HxD{73025671-91B6-473C-B0EE-6EAB6FD0E6DE}) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETWORKAREA,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetWindowTextLength() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\Documents and Settings\r32\Mis documentos\Tools\HxD\HxD.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETKEYBOARDCUES,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetForegroundWindow() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\WINDOWS\system32\Msimtf.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SetTimer(1098a) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FindWindow(Shell_TrayWnd,(null)) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenProcess(explorer.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(xpsp2res.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(xpsp3res.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SystemParametersInfo(SPI_GETFONTSMOOTHINGTYPE,0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
SetTimer(0) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(MSCTF.Shared.MUTEX.EBH) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetKeyState() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenSCManager((null),(null)) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenService(AudioSrv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(rpcrt4.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(wdmaud.drv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(setupapi.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetComputerName() [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
AdjustTokenPrivileges(SE_PRIVILEGE_ENABLED) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(wintrust.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(crypt32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(msasn1.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(imagehlp.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\ADVAPI32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateEvent(Global\crypt32LogoffEvent) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\setupapi.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\wdmaud.drv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(msacm32.drv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(msacm32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\msacm32.drv) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(midimap.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(MidiMapper_modLongMessage_RefCnt) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateMutex(MidiMapper_Configure) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\midimap.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(C:\WINDOWS\system32\Msctf.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\windows\system32\faultrep.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateEvent(Global\userenv: User Profile setup event) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(userenv.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(winsta.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(netapi32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(wtsapi32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\kernel32.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateFile(C:\DOCUME~1\r32\CONFIG~1\Temp\74b4_appcompat.txt) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateToolhelp32Snapshot(TH32C2_SNAPMODULE,964) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
LoadLibrary(c:\windows\system32\apphelp.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
FreeLibrary(C:\WINDOWS\system32\apphelp.dll) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
CreateProcess((null),C:\WINDOWS\system32\dwwin.exe -x -s 456,C:\WINDOWS\system32) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(winlogon.EXE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
GetModuleHandle(advapi32) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
VirtualAllocEx(c:\windows\system32\dwwin.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenProcess(dwwin.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
WriteProcessMemory(c:\windows\system32\dwwin.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
VirtualAllocEx(c:\windows\system32\dwwin.exe,MEM_RESERVE,PAGE_READWRITE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
Executing: c:\windows\system32\dwwin.exe
LoadLibrary(advapi32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(comctl32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(gdi32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(kernel32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(oleaut32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(msvcrt.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(ole32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(shell32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(shlwapi.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(urlmon.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(iertutil.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(user32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(version.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(wininet.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(normaliz.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(shimeng.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\apppatch\acgenral.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(kernel32.dll) [c:\windows\system32\dwwin.exe]
VirtualQueryEx(c:\windows\system32\dwwin.exe) [c:\windows\system32\dwwin.exe]
CreateMutex(SHIMLIB_LOG_MUTEX) [c:\windows\system32\dwwin.exe]
LoadLibrary(winmm.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(msacm32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(userenv.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(uxtheme.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(lz32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(lz32.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(Kernel32) [c:\windows\system32\dwwin.exe]
GetModuleHandle(LPK.DLL) [c:\windows\system32\dwwin.exe]
OpenProcess(dwwin.exe) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\windows\system32\dwwin.exe]
GetModuleHandle(USER32) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETDRAGFULLWINDOWS,4) [c:\windows\system32\dwwin.exe]
OpenProcessToken(C:\WINDOWS\system32\dwwin.exe) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETNONCLIENTMETRICS,500) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETMOUSEHOVERTIME,0) [c:\windows\system32\dwwin.exe]
LoadLibrary(imm32.dll) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETHIGHCONTRAST,12) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETMENUDROPALIGNMENT,0) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETFLATMENU,0) [c:\windows\system32\dwwin.exe]
ResumeThread() [c:\windows\system32\dwwin.exe]
GetModuleHandle(Advapi32.dll) [c:\windows\system32\dwwin.exe]
CreateEvent(DINPUTWINMM) [c:\windows\system32\dwwin.exe]
CreateEvent(Global\userenv: User Profile setup event) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\lz32.dll) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETWORKAREA,0) [c:\windows\system32\dwwin.exe]
IsDebuggerPresent() [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\UxTheme.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(riched20.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(shfolder.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\SHELL32.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\shfolder.dll) [c:\windows\system32\dwwin.exe]
BitBlt() [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\msctf.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(C:\WINDOWS\system32\imm32.dll) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
GetModuleHandle(C:\WINDOWS\system32\KERNEL32) [c:\windows\system32\dwwin.exe]
CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1202660629-1957994488-1003MUTEX.DefaultS-1-5-21-1482476501-1202660629-1957994488-1003) [c:\windows\system32\dwwin.exe]
SetTimer(20996) [c:\windows\system32\dwwin.exe]
FreeLibrary() [c:\windows\system32\dwwin.exe]
CreateFile(C:\DOCUME~1\r32\CONFIG~1\Temp\597A56.dmp) [c:\windows\system32\dwwin.exe]
GetModuleHandle(NTDLL.DLL) [c:\windows\system32\dwwin.exe]
LoadLibrary(psapi.dll) [c:\windows\system32\dwwin.exe]
OpenProcess(HxD.exe) [c:\windows\system32\dwwin.exe]
ReadProcessMemory(c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe) [c:\windows\system32\dwwin.exe]
CreateToolhelp32Snapshot(TH32C2_SNAPTHREAD,964) [c:\windows\system32\dwwin.exe]
QuerySystemInformation() [c:\windows\system32\dwwin.exe]
SuspendThread(1808) [c:\windows\system32\dwwin.exe]
SuspendThread(1800) [c:\windows\system32\dwwin.exe]
SuspendThread(1796) [c:\windows\system32\dwwin.exe]
SuspendThread(1792) [c:\windows\system32\dwwin.exe]
CreateToolhelp32Snapshot(TH32C2_SNAPALL,964) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\ntdll.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\ntdll.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\kernel32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\USER32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\GDI32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\IMM32.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\ADVAPI32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\rpcrt4.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\RPCRT4.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\secur32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\Secur32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\OLEAUT32.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\msvcrt.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\ole32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\VERSION.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\SHLWAPI.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\WININET.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\Normaliz.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\URLMON.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\iertutil.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\WINMM.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\MSCTF.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\PSAPI.DLL) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\MSACM32.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\USERENV.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(ntdll) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\3082\dwintl.dll) [c:\windows\system32\dwwin.exe]
InternetGetConnectedState() [c:\windows\system32\dwwin.exe]
GetUserName() [c:\windows\system32\dwwin.exe]
OpenMutex(Local\_!MSFTHISTORY!_) [c:\windows\system32\dwwin.exe]
GetComputerName() [c:\windows\system32\dwwin.exe]
CreateMutex(Local\_!MSFTHISTORY!_) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\c:!documents and settings!r32!configuración local!archivos temporales de internet!content.ie5!) [c:\windows\system32\dwwin.exe]
CreateMutex(Local\c:!documents and settings!r32!configuración local!archivos temporales de internet!content.ie5!) [c:\windows\system32\dwwin.exe]
CreateFile(C:\Documents and Settings\r32\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\c:!documents and settings!r32!cookies!) [c:\windows\system32\dwwin.exe]
CreateMutex(Local\c:!documents and settings!r32!cookies!) [c:\windows\system32\dwwin.exe]
CreateFile(C:\Documents and Settings\r32\Cookies\index.dat) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\c:!documents and settings!r32!configuración local!historial!history.ie5!) [c:\windows\system32\dwwin.exe]
CreateMutex(Local\c:!documents and settings!r32!configuración local!historial!history.ie5!) [c:\windows\system32\dwwin.exe]
CreateFile(C:\Documents and Settings\r32\Configuración local\Historial\History.IE5\index.dat) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\WininetStartupMutex) [c:\windows\system32\dwwin.exe]
LoadLibrary(ws2_32) [c:\windows\system32\dwwin.exe]
LoadLibrary(ws2_32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(ws2help.dll) [c:\windows\system32\dwwin.exe]
GetModuleHandle(shlwapi.dll) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\WininetConnectionMutex) [c:\windows\system32\dwwin.exe]
OpenMutex(Local\WininetProxyRegistryMutex) [c:\windows\system32\dwwin.exe]
LoadLibrary(rasapi32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(rasman.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(netapi32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(tapi32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(rtutils.dll) [c:\windows\system32\dwwin.exe]
CreateMutex(RasPbFile) [c:\windows\system32\dwwin.exe]
OpenMutex(RasPbFile) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\RASAPI32.dll) [c:\windows\system32\dwwin.exe]
RasEnumEntries() [c:\windows\system32\dwwin.exe]
OpenSCManager((null),(null)) [c:\windows\system32\dwwin.exe]
OpenService(RASMAN) [c:\windows\system32\dwwin.exe]
LoadLibrary(msapsspc.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(msvcrt40.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\msapsspc.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(schannel.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(crypt32.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(msasn1.dll) [c:\windows\system32\dwwin.exe]
CreateEvent(Global\crypt32LogoffEvent) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\schannel.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(digest.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\digest.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(msnsspc.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\msnsspc.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(c:\windows\system32\msv1_0.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(cryptdll.dll) [c:\windows\system32\dwwin.exe]
LoadLibrary(iphlpapi.dll) [c:\windows\system32\dwwin.exe]
lstrcmpi(COMPUTERNAME,TEMP) [c:\windows\system32\dwwin.exe]
lstrcmpi(COMPUTERNAME,TMP) [c:\windows\system32\dwwin.exe]
OpenService(Sens) [c:\windows\system32\dwwin.exe]
LoadLibrary(sensapi.dll) [c:\windows\system32\dwwin.exe]
OpenProcess(ctfmon.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(SbieCtrl.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(explorer.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(u1210.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(wireshark.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(sniff_hit.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(iexplore.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(firefox.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(VBoxTray.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(procexp.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(BSA.EXE) [c:\windows\system32\dwwin.exe]
OpenProcess(XueTr.exe) [c:\windows\system32\dwwin.exe]
OpenProcess(dumpcap.exe) [c:\windows\system32\dwwin.exe]
GetSystemDefaultLangID() [c:\windows\system32\dwwin.exe]
SetWindowPos(20994,TOPMOST) [c:\windows\system32\dwwin.exe]
GetForegroundWindow() [c:\windows\system32\dwwin.exe]
FindWindow(Shell_TrayWnd,(null)) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETICONTITLELOGFONT,60) [c:\windows\system32\dwwin.exe]
OpenProcess(csrss.exe) [c:\windows\system32\dwwin.exe]
CreateMutex(MSCTF.Shared.MUTEX.EBH) [c:\windows\system32\dwwin.exe]
GetModuleHandle(ole32.dll) [c:\windows\system32\dwwin.exe]
DeleteFile(C:\DOCUME~1\r32\CONFIG~1\Temp\597A56.dmp) [c:\windows\system32\dwwin.exe]
DeleteFile(C:\DOCUME~1\r32\CONFIG~1\Temp\74b4_appcompat.txt) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\3082\dwintl.dll) [c:\windows\system32\dwwin.exe]
ExitProcess(0) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\rasman.dll) [c:\windows\system32\dwwin.exe]
FreeLibrary(C:\WINDOWS\system32\rtutils.dll) [c:\windows\system32\dwwin.exe]
VirtualAllocEx(c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
VirtualAllocEx(c:\windows\system32\drwtsn32.exe,MEM_COMMIT,PAGE_READWRITE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
OpenProcess(drwtsn32.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
WriteProcessMemory(c:\windows\system32\drwtsn32.exe) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
VirtualAllocEx(c:\windows\system32\drwtsn32.exe,MEM_RESERVE,PAGE_READWRITE) [c:\documents and settings\r32\mis documentos\tools\hxd\hxd.exe]
Executing: c:\windows\system32\drwtsn32.exe
LoadLibrary(msvcrt.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(advapi32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(kernel32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(gdi32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(user32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(dbgeng.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(dbghelp.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(version.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(shimeng.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(c:\windows\apppatch\acgenral.dll) [c:\windows\system32\drwtsn32.exe]
GetModuleHandle(kernel32.dll) [c:\windows\system32\drwtsn32.exe]
VirtualQueryEx(c:\windows\system32\drwtsn32.exe) [c:\windows\system32\drwtsn32.exe]
CreateMutex(SHIMLIB_LOG_MUTEX) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(winmm.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(ole32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(oleaut32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(msacm32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(shell32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(shlwapi.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(userenv.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(uxtheme.dll) [c:\windows\system32\drwtsn32.exe]
GetModuleHandle(lz32.dll) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(lz32.dll) [c:\windows\system32\drwtsn32.exe]
CreateEvent(DINPUTWINMM) [c:\windows\system32\drwtsn32.exe]
GetModuleHandle(Kernel32) [c:\windows\system32\drwtsn32.exe]
LoadLibrary(comctl32.dll) [c:\windows\system32\drwtsn32.exe]
GetModuleHandle(EXPLORER.EXE) [c:\windows\system32\dwwin.exe]
SystemParametersInfo(SPI_GETWHEELSCROLLLINES,0) [c:\windows\system32\drwtsn32.exe]












