The downloaded malware samples are queued into a
behavior-based analysis system. This malware analysis
system uses virtual machines with a clean Microsoft
Windows XP operating system patched to Service Pack
2. The sandbox automatically attempts a deliberate infection
from a clean reverted system state and runs for
a timeout of 60 seconds.