Loads The following DLL(s)[Dynamic Link Library] when this malware is executed :-
%windir%\system32\ntdll.dll
%windir%\system32\kernel32.dll
%windir%\system32\mfc42.dll
%windir%\system32\msvcrt.dll
%windir%\system32\gdi32.dll
%windir%\system32\user32.dll
%windir%\system32\advapi32.dll
%windir%\system32\rpcrt4.dll
%windir%\system32\shell32.dll
%windir%\system32\shlwapi.dll
%windir%\system32\vsmvhk.dll
%windir%\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\
%windir%\system32\comctl32.dll
%windir%\system32\oleaut32.dll
%windir%\system32\ole32.dll
%windir%\system32\wsock32.dll
%windir%\system32\ws2_32.dll
%windir%\system32\ws2help.dll
%windir%\system32\pstorec.dll
%windir%\system32\atl.dll
%windir%\system32\wship6.dll
%windir%\system32\secur32.dll
comctl32.dll
comctl32.dll
version.dll
%windir%\system32\shimeng.dll
%windir%\apppatch\acgenral.dll
%windir%\system32\winmm.dll
%windir%\system32\msacm32.dll
%windir%\system32\version.dll
%windir%\system32\userenv.dll
%windir%\system32\uxtheme.dll
Creates the following child process(s) on execution:
regsvr32 /s %workingdir%\6a841cbb01a4ad195the007guard.ocx
regsvr32 /s %systemdrive%\progra~1\the guard\the007guard.ocx
regsvr32 /s d:\progra~1\the guard\the007guard.ocx
regsvr32 /s e:\progra~1\the guard\the007guard.ocx