<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
  <report_version>
	  <major>3</major>
		<minor>2</minor>
	</report_version>
	<configuration>
	  <time_needed>123 s</time_needed>
		<report_created>02/05/11, 06:04:33 UTC</report_created>
		<termination_reason>All tracked processes have exited</termination_reason>
		<ttanalyze_version>
		  <prog_version>1.74.3362</prog_version>
			<svn_revision>$Revision: 3393 $</svn_revision>
			<build_date>Jan 31 2011 10:28:23</build_date>
		</ttanalyze_version>
	</configuration>
	<summary>
	  <auto_start>false</auto_start>
		<internet_settings>true</internet_settings>
		<bho>false</bho>
		<win_dir_copy>false</win_dir_copy>
		<av_kill>false</av_kill>
		<com_object>false</com_object>
		<dlf>false</dlf>
		<ircbot>false</ircbot>
		<spambot>false</spambot>
		<addressscan>false</addressscan>
		<portscan>false</portscan>
		<file_modification_destruction>false</file_modification_destruction>
		<process_spawn>true</process_spawn>
		<all_reg_activities>true</all_reg_activities>
		<write_to_foreign_mem_area>true</write_to_foreign_mem_area>
		<install_service>false</install_service>
		<load_driver>false</load_driver>
		<install_ie_toolbar>false</install_ie_toolbar>
		<disable_win_update>false</disable_win_update>
		<change_win_firewall_settings>false</change_win_firewall_settings>
		<harvesting_emails>false</harvesting_emails>
		<mod_sys_files>false</mod_sys_files>
		<modify_files_only_in_user_dir>false</modify_files_only_in_user_dir>
		<packed_binary>false</packed_binary>
		<av_hit>true</av_hit>
		<crash>true</crash>
		<autorun>false</autorun>
		<severity_level>5</severity_level>
	</summary>
	<analysis_subject>
	  <general>
		  <id>2</id>
			<parent_id>1</parent_id>
			<analysis_reason>Primary Analysis Subject</analysis_reason>
			<submission_fn>40488567</submission_fn>
			<virtual_fn>40488567.exe</virtual_fn>
			<virtual_path>C:\40488567.exe</virtual_path>
			<arguments>"C:\40488567.exe" </arguments>
			<status>dead</status>
			<exit_code>-1073741794</exit_code>
			<md5>88b1a1ffb726b912add47d22284190c2</md5>
			<sha1>e31a6de19ed73f69287316d4db59633f27420631</sha1>
			<file_size>1482752</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x763B0000" base_name="comdlg32.dll" full_name="C:\WINDOWS\system32\comdlg32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x5D090000" base_name="COMCTL32.dll" full_name="C:\WINDOWS\system32\COMCTL32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x00E00000" base_name="xpsp2res.dll" full_name="C:\WINDOWS\system32\xpsp2res.dll" is_load_time_dependency="0" load_time="2" size="0x002C5000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x69450000" base_name="faultrep.dll" full_name="C:\WINDOWS\system32\faultrep.dll" is_load_time_dependency="0" load_time="2" size="0x00016000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="0" load_time="2" size="0x00017000"/>
			<loaded_dll base_address="0x74ED0000" base_name="wbemsvc.dll" full_name="C:\WINDOWS\system32\wbem\wbemsvc.dll" is_load_time_dependency="0" load_time="2" size="0x0000E000"/>
			<loaded_dll base_address="0x74EF0000" base_name="wbemprox.dll" full_name="C:\WINDOWS\system32\wbem\wbemprox.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x75290000" base_name="wbemcomn.dll" full_name="C:\WINDOWS\system32\wbem\wbemcomn.dll" is_load_time_dependency="0" load_time="2" size="0x00037000"/>
			<loaded_dll base_address="0x75690000" base_name="fastprox.dll" full_name="C:\WINDOWS\system32\wbem\fastprox.dll" is_load_time_dependency="0" load_time="2" size="0x00076000"/>
			<loaded_dll base_address="0x76080000" base_name="MSVCP60.dll" full_name="C:\WINDOWS\system32\MSVCP60.dll" is_load_time_dependency="0" load_time="2" size="0x00065000"/>
			<loaded_dll base_address="0x76360000" base_name="WINSTA.dll" full_name="C:\WINDOWS\system32\WINSTA.dll" is_load_time_dependency="0" load_time="2" size="0x00010000"/>
			<loaded_dll base_address="0x767A0000" base_name="NTDSAPI.dll" full_name="C:\WINDOWS\system32\NTDSAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00013000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="0" load_time="2" size="0x000B4000"/>
			<loaded_dll base_address="0x76F20000" base_name="DNSAPI.dll" full_name="C:\WINDOWS\system32\DNSAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00027000"/>
			<loaded_dll base_address="0x76F50000" base_name="WTSAPI32.dll" full_name="C:\WINDOWS\system32\WTSAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x76F60000" base_name="WLDAP32.dll" full_name="C:\WINDOWS\system32\WLDAP32.dll" is_load_time_dependency="0" load_time="2" size="0x0002C000"/>
			<loaded_dll base_address="0x76FD0000" base_name="CLBCATQ.DLL" full_name="C:\WINDOWS\system32\CLBCATQ.DLL" is_load_time_dependency="0" load_time="2" size="0x0007F000"/>
			<loaded_dll base_address="0x77050000" base_name="COMRes.dll" full_name="C:\WINDOWS\system32\COMRes.dll" is_load_time_dependency="0" load_time="2" size="0x000C5000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="0" load_time="2" size="0x0008B000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="0" load_time="2" size="0x000AA000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="0" load_time="2" size="0x0013D000"/>
			<loaded_dll base_address="0x77920000" base_name="SETUPAPI.dll" full_name="C:\WINDOWS\system32\SETUPAPI.dll" is_load_time_dependency="0" load_time="2" size="0x000F3000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="0" load_time="2" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
			<loaded_dll base_address="0x77B40000" base_name="apphelp.dll" full_name="C:\WINDOWS\system32\apphelp.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\APPID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}" value_data="winmgmt" value_name="LocalService"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\INPROCSERVER32" value_data="C:\WINDOWS\system32\wbem\fastprox.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\INPROCSERVER32" value_data="C:\WINDOWS\system32\wbem\wbemprox.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\INPROCSERVER32" value_data="C:\WINDOWS\system32\wbem\wbemsvc.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}" value_data="{8BC3F05E-D86B-11D0-A075-00C04FB68820}" value_name="AppID"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\INPROCSERVER32" value_data="C:\WINDOWS\system32\wbem\fastprox.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{027947E1-D731-11CE-A357-000000000001}\PROXYSTUBCLSID32" value_data="{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\PROXYSTUBCLSID32" value_data="{7C857801-7381-11CF-884D-00AA004B2E24}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{423EC01E-2E35-11D2-B604-00104B703EFD}\PROXYSTUBCLSID32" value_data="{7C857801-7381-11CF-884D-00AA004B2E24}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{9556DC99-828C-11CF-A37E-00AA003240C7}\PROXYSTUBCLSID32" value_data="{D68AF00A-29CB-43FA-8504-CE99A996D9EA}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\PROXYSTUBCLSID32" value_data="{7C857801-7381-11CF-884D-00AA004B2E24}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{F309AD18-D86A-11D0-A075-00C04FB68820}\PROXYSTUBCLSID32" value_data="{7C857801-7381-11CF-884D-00AA004B2E24}" value_name=""/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\Setup" value_data="\" value_name="OsLoaderPath"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\Setup" value_data="\Device\HarddiskVolume1" value_name="SystemPartition"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\COM3" value_data="1" value_name="Com+Enabled"/>
				<reg_value_read count="10" key="HKLM\Software\Microsoft\COM3" value_data="0x0700000000000000" value_name="REGDBVersion"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="AllOrNone"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="DoReport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="IncludeKernelFaults"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="IncludeMicrosoftApps"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="IncludeWindowsApps"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\PCHealth\ErrorReporting" value_data="1" value_name="ShowUI"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\WBEM\CIMOM" value_data="65536" value_name="Log File Max Size"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\WBEM\CIMOM" value_data="1" value_name="Logging"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\WBEM\CIMOM" value_data="C:\WINDOWS\system32\WBEM\Logs\" value_name="Logging Directory"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\WBEM\CIMOM" value_data="712" value_name="ProcessID"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\WBEM\CIMOM" value_data="%SystemRoot%\system32\WBEM\Repository" value_name="Repository Directory"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug" value_data="1" value_name="Auto"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug" value_data="drwtsn32 -p %ld -e %ld -g" value_name="Debugger"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="%SystemRoot%\inf" value_name="DevicePath"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Setup" value_data="%SystemRoot%\Driver Cache" value_name="DriverCachePath"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Setup" value_data="0" value_name="LogLevel"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Setup" value_data="c:\windows\ServicePackFiles\ServicePackCache" value_name="ServicePackCachePath"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Setup" value_data="D:\" value_name="ServicePackSourcePath"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Setup" value_data="D:\" value_name="SourcePath"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="AuthenticodeEnabled"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="262144" value_name="DefaultLevel"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="PolicyScope"/>
				<reg_value_read count="2" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0x5eab304f957a49896a006c1c31154015" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="779" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0x67b0d48b343a3fd3bce9dc646704f394" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="517" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0x327802dcfef8c893dc8ab006dd847d1d" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="918" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0xbd9a2adb42ebd8560e250e4df8162f67" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="229" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0x386b085f84ecf669d36b956a22c01e80" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="370" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK*" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ProductOptions" value_data="WinNT" value_name="ProductType"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSUserEnabled"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\LDAP" value_data="1" value_name="LdapClientIntegrity"/>
				<reg_value_read count="3" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="" value_name="Domain"/>
				<reg_value_read count="3" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="pc" value_name="Hostname"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="0" value_name="UseDomainNameDevolution"/>
				<reg_value_read count="3" key="HKLM\System\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\System\WPA\PnP" value_data="1274198464" value_name="seed"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files" value_name="Cache"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings" value_name="Local Settings"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\My Documents" value_name="Personal"/>
				<reg_key_monitored count="3" key="HKLM\Software\Classes" notify_filter="Key Change,Value Change" watch_subtree="1"/>
				<reg_key_monitored count="2" key="HKLM\Software\Classes\CLSID" notify_filter="Key Change,Value Change" watch_subtree="1"/>
				<reg_key_monitored count="6" key="HKLM\Software\Microsoft\COM3" notify_filter="Key Change,Value Change" watch_subtree="1"/>
				<reg_key_monitored count="3" key="HKU" notify_filter="Key Change,Value Change" watch_subtree="1"/>
			</registry_activities>
			<file_activities>
			  <file_created name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b99c_appcompat.txt"/>
				<file_modified name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b99c_appcompat.txt"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\WINDOWS\Registration\R000000000007.clb"/>
				<file_read name="C:\WINDOWS\system32\winsock.dll"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\CLBCATQ.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMCTL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMRes.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\DNSAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSVCP60.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\NTDSAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SETUPAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WINSTA.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WTSAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\advapi32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\drwtsn32.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\dwwin.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\faultrep.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\gdi32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\kernel32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ntdll.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ole32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\oleaut32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\rpcss.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\shell32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\user32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\wbem\fastprox.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\wbem\wbemcomn.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\wbem\wbemprox.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\wbem\wbemsvc.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\wininet.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\winlogon.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\winsock.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\xpsp2res.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
				<device_control_communication control_code="0x00390008" count="8" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="9" file="PIPE\lsarpc"/>
			</file_activities>
			<process_activities>
			  <remote_thread_created process="C:\WINDOWS\system32\dwwin.exe"/>
				<remote_thread_created process="C:\WINDOWS\system32\drwtsn32.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\drwtsn32.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\dwwin.exe"/>
				<foreign_mem_area_write process="C:\WINDOWS\system32\drwtsn32.exe"/>
				<foreign_mem_area_write process="C:\WINDOWS\system32\dwwin.exe"/>
				<process_created cmd_line="" description="process_spawn" exe_name="C:\WINDOWS\system32\dwwin.exe"/>
				<process_created cmd_line="C:\WINDOWS\system32\dwwin.exe -x -s 392" description="process_spawn" exe_name=""/>
				<process_created cmd_line="" description="process_spawn" exe_name="C:\WINDOWS\system32\drwtsn32.exe"/>
				<process_created cmd_line="C:\WINDOWS\system32\drwtsn32 -p 1576 -e 368 -g" description="process_spawn" exe_name=""/>
			</process_activities>
			<misc_activities>
			  <mutex_created name="DBWinMutex"/>
				<exception_occurred count="1" description="Exception 0x40010006 at 0x7c812aeb"/>
				<exception_occurred count="2" description="Exception 0xc000001e at 0xd3ad29"/>
			</misc_activities>
		</activities>
		<ikarus_scanner>
		  <sig id="50488567" name="Trojan.Win32.Rimecud"/>
		</ikarus_scanner>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>3</id>
			<parent_id>2</parent_id>
			<analysis_reason>Started by 40488567.exe</analysis_reason>
			<virtual_fn>dwwin.exe</virtual_fn>
			<virtual_path>C:\WINDOWS\system32\dwwin.exe</virtual_path>
			<arguments>C:\WINDOWS\system32\dwwin.exe -x -s 392</arguments>
			<status>dead</status>
			<exit_code>0</exit_code>
			<md5>86042f6f6a5287eaf9379c91d0bf72b6</md5>
			<sha1>532bf74e6aead7438aa7264d01759a065410ee68</sha1>
			<file_size>180224</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.DLL" full_name="C:\WINDOWS\system32\ADVAPI32.DLL" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x5D090000" base_name="COMCTL32.DLL" full_name="C:\WINDOWS\system32\COMCTL32.DLL" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.DLL" full_name="C:\WINDOWS\system32\OLEAUT32.DLL" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.DLL" full_name="C:\WINDOWS\system32\SHELL32.DLL" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x7E1E0000" base_name="URLMON.DLL" full_name="C:\WINDOWS\system32\URLMON.DLL" is_load_time_dependency="1" load_time="1" size="0x000A2000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.DLL" full_name="C:\WINDOWS\system32\WININET.DLL" is_load_time_dependency="1" load_time="1" size="0x000AA000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="1" load_time="1" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
			<loaded_dll base_address="0x6F880000" base_name="AcGenral.DLL" full_name="C:\WINDOWS\AppPatch\AcGenral.DLL" is_load_time_dependency="1" load_time="1" size="0x001CA000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x77BE0000" base_name="MSACM32.dll" full_name="C:\WINDOWS\system32\MSACM32.dll" is_load_time_dependency="1" load_time="1" size="0x00015000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
			<loaded_dll base_address="0x5AD70000" base_name="UxTheme.dll" full_name="C:\WINDOWS\system32\UxTheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x314C0000" base_name="dwintl.dll" full_name="C:\WINDOWS\system32\1033\dwintl.dll" is_load_time_dependency="0" load_time="2" size="0x0000C000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="0" load_time="2" size="0x00017000"/>
			<loaded_dll base_address="0x722B0000" base_name="sensapi.dll" full_name="C:\WINDOWS\system32\sensapi.dll" is_load_time_dependency="0" load_time="2" size="0x00005000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="0" load_time="2" size="0x0004C000"/>
			<loaded_dll base_address="0x74E30000" base_name="riched20.dll" full_name="C:\WINDOWS\system32\riched20.dll" is_load_time_dependency="0" load_time="2" size="0x0006D000"/>
			<loaded_dll base_address="0x76390000" base_name="imm32.dll" full_name="C:\WINDOWS\system32\imm32.dll" is_load_time_dependency="0" load_time="2" size="0x0001D000"/>
			<loaded_dll base_address="0x76780000" base_name="shfolder.dll" full_name="C:\WINDOWS\system32\shfolder.dll" is_load_time_dependency="0" load_time="2" size="0x00009000"/>
			<loaded_dll base_address="0x76BF0000" base_name="PSAPI.DLL" full_name="C:\WINDOWS\system32\PSAPI.DLL" is_load_time_dependency="0" load_time="2" size="0x0000B000"/>
			<loaded_dll base_address="0x76E80000" base_name="rtutils.dll" full_name="C:\WINDOWS\system32\rtutils.dll" is_load_time_dependency="0" load_time="2" size="0x0000E000"/>
			<loaded_dll base_address="0x76E90000" base_name="rasman.dll" full_name="C:\WINDOWS\system32\rasman.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
			<loaded_dll base_address="0x76EB0000" base_name="TAPI32.dll" full_name="C:\WINDOWS\system32\TAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x0002F000"/>
			<loaded_dll base_address="0x76EE0000" base_name="RASAPI32.DLL" full_name="C:\WINDOWS\system32\RASAPI32.DLL" is_load_time_dependency="0" load_time="2" size="0x0003C000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" description="internet_settings" key="HKLM\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_modified count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\All Users\Application Data" value_name="Common AppData"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5" value_name="Directory"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths" value_data="4" value_name="Paths"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path1" value_data="40852" value_name="CacheLimit"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path1" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache1" value_name="CachePath"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path2" value_data="40852" value_name="CacheLimit"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path2" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache2" value_name="CachePath"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path3" value_data="40852" value_name="CacheLimit"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path3" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache3" value_name="CachePath"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path4" value_data="40852" value_name="CacheLimit"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Path4" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache4" value_name="CachePath"/>
				<reg_value_modified count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="AppData"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files" value_name="Cache"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Cookies" value_name="Cookies"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Local Settings\History" value_name="History"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\My Documents" value_name="Personal"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000000500000009000000000000000000000000000000000000000000" value_name="SavedLegacySettings"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP" value_data="0x00000000" value_name="Default"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP" value_data="%SystemRoot%\system32\iedkcs32.dll" value_name="DllFile"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP" value_data=".ins" value_name="FileExtensions"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG" value_data="0x01000000" value_name="Default"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG" value_data="%SystemRoot%\system32\jsproxy.dll" value_name="DllFile"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG" value_data=".pac;.jvs;.js" value_name="FileExtensions"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG" value_data="0x01000000" value_name="Flags"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\CTF\SystemShared\" value_data="0" value_name="CUAS"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0x00000000" value_name="UrlEncoding"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0x01000000100000000204000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0x01000000100000001100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0x0100000010000000550000001e000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0x01000000100000000200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0x01000000120000006001000016000000610100001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0x010000001000000006000000120000000700000012000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0x0100000010000000420000001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0x01000000100000003100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0x01000000100000003001000016000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0x01000000100000002200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS" value_data="1" value_name="*"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL" value_data="1" value_name="*"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Tracing" value_data="0" value_name="EnableConsoleTracing"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="ConsoleTracingMask"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableConsoleTracing"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableFileTracing"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="%windir%\tracing" value_name="FileDirectory"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="FileTracingMask"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="1048576" value_name="MaxFileSize"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion" value_data="0xa40000000300000037363438372d3634302d313435373233362d32333833" value_name="DigitalProductId"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug" value_data="drwtsn32 -p %ld -e %ld -g" value_name="Debugger"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="midimapper"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="C:\WINDOWS\system32\iac25_32.ax" value_name="msacm.iac2"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="imaadp32.acm" value_name="msacm.imaadpcm"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.l3acm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msadpcm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msaudio1"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msg711"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msg723"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="msgsm32.acm" value_name="msacm.msgsm610"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.sl_anet"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.trspch"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.I420"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M261"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M263"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.cvid"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv31"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv32"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv41"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv50"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iyuv"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.mrle"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.msvc"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.uyvy"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yuy2"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvu9"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvyu"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="wavemapper"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="All Users" value_name="AllUsersProfile"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="Default User" value_name="DefaultUserProfile"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="%SystemDrive%\Documents and Settings" value_name="ProfilesDirectory"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-1425521274-308236825-500" value_data="%SystemDrive%\Documents and Settings\Administrator" value_name="ProfileImagePath"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files\Common Files" value_name="CommonFilesDir"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files" value_name="ProgramFilesDir"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%ALLUSERSPROFILE%\Application Data" value_name="Common AppData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="5" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm" value_data="1" value_name="wheel"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ProductOptions" value_data="WinNT" value_name="ProductType"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32\cmd.exe" value_name="ComSpec"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="NO" value_name="FP_NO_HOST_CHECK"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="1" value_name="NUMBER_OF_PROCESSORS"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="Windows_NT" value_name="OS"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH" value_name="PATHEXT"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86" value_name="PROCESSOR_ARCHITECTURE"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86 Family 6 Model 3 Stepping 3, GenuineIntel" value_name="PROCESSOR_IDENTIFIER"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="6" value_name="PROCESSOR_LEVEL"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="0303" value_name="PROCESSOR_REVISION"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem" value_name="Path"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TEMP"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TMP"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%" value_name="windir"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Terminal Server" value_data="0" value_name="TSUserEnabled"/>
				<reg_value_read count="1" key="HKLM\System\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TEMP"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TMP"/>
				<reg_value_read count="6" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle" value_data="1" value_name="Language Hotkey"/>
				<reg_value_read count="6" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle" value_data="2" value_name="Layout Hotkey"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="1" value_name="EnableHttp1_1"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="1" value_name="EnableNegotiate"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="multipart/mixed multipart/x-mixed-replace multipart/x-byteranges " value_name="MimeExclusionListForCache"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0x01000000" value_name="WarnOnPost"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Settings" value_data="0,0,255" value_name="Anchor Color"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Multimedia\Audio" value_data="CD Quality,Radio Quality,Telephone Quality" value_name="SystemFormats"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" value_data="1" value_name="ParseAutoexec"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Application Data" value_name="AppData"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings\Temporary Internet Files" value_name="Cache"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Cookies" value_name="Cookies"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings\History" value_name="History"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings" value_name="Local Settings"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\My Documents" value_name="Personal"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache" value_data="Client UrlCache MMF Ver 5.2" value_name="Signature"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="163410" value_name="CacheLimit"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="" value_name="CachePrefix"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="1" value_name="PerUserItem"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="8192" value_name="CacheLimit"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="Cookie:" value_name="CachePrefix"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="1" value_name="PerUserItem"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="8192" value_name="CacheLimit"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="Visited:" value_name="CachePrefix"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="1" value_name="PerUserItem"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000000200000009000000000000000000000000000000000000000000" value_name="DefaultConnectionSettings"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000000400000009000000000000000000000000000000000000000000" value_name="SavedLegacySettings"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="APPDATA"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="" value_name="CLIENTNAME"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="C:" value_name="HOMEDRIVE"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="\Documents and Settings\Administrator" value_name="HOMEPATH"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="" value_name="HOMESHARE"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="\\PC" value_name="LOGONSERVER"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="Console" value_name="SESSIONNAME"/>
				<reg_key_monitored count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" notify_filter="Attributes Change,Value Change,Security Descriptor Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <file_created name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7E339.dmp"/>
				<file_deleted name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7E339.dmp"/>
				<file_deleted name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b99c_appcompat.txt"/>
				<file_modified name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7E339.dmp"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\40488567.exe"/>
				<file_read name="C:\WINDOWS\win.ini"/>
				<file_read name="PIPE\lsarpc"/>
				<file_read name="c:\autoexec.bat"/>
				<section_object_created file_name="C:\40488567.exe" section_name=""/>
				<section_object_created file_name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7E339.dmp" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\AppPatch\AcGenral.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\1033\dwintl.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ADVAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\CLBCATQ.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMCTL32.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMCTL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMRes.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\CRYPT32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\GDI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSACM32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSASN1.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSCTF.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\NETAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\OLEAUT32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\PSAPI.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\RASAPI32.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\RPCRT4.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SETUPAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHLWAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Secur32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ShimEng.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\TAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\URLMON.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\USER32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\USERENV.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\UxTheme.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\VERSION.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WINMM.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WINSTA.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WTSAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comdlg32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\faultrep.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\imm32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\kernel32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\msvcrt.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ntdll.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ole32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\rasman.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\riched20.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\rtutils.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\sensapi.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\shfolder.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\xpsp2res.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
				<fs_control_communication control_code="0x00090028" count="1" file="C:\WINDOWS\system32"/>
				<device_control_communication control_code="0x00390008" count="8" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="16" file="PIPE\lsarpc"/>
			</file_activities>
			<process_activities>
			  <foreign_mem_area_read process="C:\40488567.exe"/>
			</process_activities>
			<misc_activities>
			  <mutex_created name="CTF.Asm.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="CTF.Compart.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="CTF.LBES.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="CTF.Layouts.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="CTF.TMD.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="CTF.TimListCache.FMPDefaultS-1-5-21-842925246-1425521274-308236825-500MUTEX.DefaultS-1-5-21-842925246-1425521274-308236825-500"/>
				<mutex_created name="MSCTF.Shared.MUTEX.IM"/>
				<mutex_created name="SHIMLIB_LOG_MUTEX"/>
				<mutex_created name="ZonesCacheCounterMutex"/>
				<mutex_created name="ZonesCounterMutex"/>
				<mutex_created name="ZonesLockedCacheCounterMutex"/>
				<key_was_checked count="2" key="VK_MENU (18)"/>
				<key_was_checked count="2" key="VK_CONTROL (17)"/>
				<key_was_checked count="2" key="VK_SHIFT (16)"/>
				<key_was_checked count="2" key="VK_LWIN (91)"/>
				<key_was_checked count="2" key="VK_RWIN (92)"/>
			</misc_activities>
		</activities>
		<popups>
		  <popup number_of_popups="1" window_name="SWiSH Max3 Application">&amp;Don't Send
SWiSH Max3 Application has encountered a problem and needs to close.  We are sorry for the inconvenience.
SWiSH Max3 Application has encountered a problem and needs to close.  We are sorry for the inconvenience.
If you were in the middle of something, the information you were working on might be lost.
Please tell Microsoft about this problem.
We have created an error report that you can send to us.  We will treat this report as confidential and anonymous.
To see what data this error report contains,
Details
&amp;Send Error Report
 <screenshot src="1.png" src_small="1_thumb.jpg"/>
			</popup>
		</popups>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>4</id>
			<parent_id>2</parent_id>
			<analysis_reason>Started by 40488567.exe</analysis_reason>
			<virtual_fn>drwtsn32.exe</virtual_fn>
			<virtual_path>C:\WINDOWS\system32\drwtsn32.exe</virtual_path>
			<arguments>C:\WINDOWS\system32\drwtsn32 -p 1576 -e 368 -g</arguments>
			<status>dead</status>
			<exit_code>0</exit_code>
			<md5>c9f5e1de6da983e89e714ed80c11f000</md5>
			<sha1>1717b633478fb107d3c26344f710328b93ae550c</sha1>
			<file_size>45568</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x6D590000" base_name="dbgeng.dll" full_name="C:\WINDOWS\system32\dbgeng.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x59A60000" base_name="DBGHELP.dll" full_name="C:\WINDOWS\system32\DBGHELP.dll" is_load_time_dependency="1" load_time="1" size="0x000A1000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
			<loaded_dll base_address="0x6F880000" base_name="AcGenral.DLL" full_name="C:\WINDOWS\AppPatch\AcGenral.DLL" is_load_time_dependency="1" load_time="1" size="0x001CA000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77BE0000" base_name="MSACM32.dll" full_name="C:\WINDOWS\system32\MSACM32.dll" is_load_time_dependency="1" load_time="1" size="0x00015000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
			<loaded_dll base_address="0x5AD70000" base_name="UxTheme.dll" full_name="C:\WINDOWS\system32\UxTheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x5F170000" base_name="ntsdexts.dll" full_name="C:\WINDOWS\system32\ntsdexts.dll" is_load_time_dependency="0" load_time="2" size="0x0000C000"/>
			<loaded_dll base_address="0x69480000" base_name="exts.dll" full_name="C:\WINDOWS\system32\exts.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
			<loaded_dll base_address="0x76BF0000" base_name="psapi.dll" full_name="C:\WINDOWS\system32\psapi.dll" is_load_time_dependency="0" load_time="2" size="0x0000B000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\All Users\Application Data" value_name="Common AppData"/>
				<reg_value_modified count="1" key="HKLM\software\microsoft\DrWatson" value_data="1" value_name="NumberOfCrashes"/>
				<reg_value_read count="1" key="HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0" value_data="x86 Family 6 Model 3 Stepping 3" value_name="Identifier"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="2600" value_name="CurrentBuildNumber"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="Uniprocessor Free" value_name="CurrentType"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="TU Wien, Campuslizenz" value_name="RegisteredOrganization"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="Ihr Benutzername" value_name="RegisteredOwner"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Windows" value_data="768" value_name="CSDVersion"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0x01000000100000000204000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0x01000000100000001100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0x0100000010000000550000001e000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0x01000000100000000200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0x01000000120000006001000016000000610100001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0x010000001000000006000000120000000700000012000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0x0100000010000000420000001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0x01000000100000003100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0x01000000100000003001000016000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0x01000000100000002200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion" value_data="Uniprocessor Free" value_name="CurrentType"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="midimapper"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.iac2"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.imaadpcm"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.l3acm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msadpcm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msaudio1"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msg711"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="msg723.acm" value_name="msacm.msg723"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msgsm610"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.sl_anet"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="tssoft32.acm" value_name="msacm.trspch"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.I420"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M261"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M263"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.cvid"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv31"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv32"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv41"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv50"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iyuv"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.mrle"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.msvc"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.uyvy"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yuy2"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvu9"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvyu"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="wavemapper"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%ALLUSERSPROFILE%\Application Data" value_name="Common AppData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm" value_data="1" value_name="wheel"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ProductOptions" value_data="WinNT" value_name="ProductType"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="1" value_name="AppendToLogFile"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="1" value_name="CrashDumpType"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="1" value_name="CreateCrashDump"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="1" value_name="DumpAllThreads"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="0" value_name="DumpSymbols"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="10" value_name="Instructions"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="10" value_name="MaximumCrashes"/>
				<reg_value_read count="2" key="HKLM\software\microsoft\DrWatson" value_data="0" value_name="NumberOfCrashes"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="0" value_name="SoundNotification"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="0" value_name="VisualNotification"/>
				<reg_value_read count="1" key="HKLM\software\microsoft\DrWatson" value_data="" value_name="WaveFile"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Multimedia\Audio" value_data="CD Quality,Radio Quality,Telephone Quality" value_name="SystemFormats"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings" value_name="Local Settings"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\My Documents" value_name="Personal"/>
			</registry_activities>
			<file_activities>
			  <directory_created name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson"/>
				<file_created name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson"/>
				<file_created name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log"/>
				<file_created name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp"/>
				<file_modified name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log"/>
				<file_modified name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\40488567.exe"/>
				<file_read name="C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log"/>
				<file_read name="C:\WINDOWS\system32\xpsp2res.dll"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\40488567.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\AppPatch\AcGenral.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ADVAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\CLBCATQ.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMCTL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\COMRes.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\CRYPT32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\DBGHELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\GDI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSACM32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSASN1.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\OLEAUT32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\RPCRT4.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHLWAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Secur32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ShimEng.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\USER32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\UxTheme.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\VERSION.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WINMM.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comdlg32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\dbgeng.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\exts.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\kernel32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\msvcrt.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ntdll.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ntsdexts.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ole32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\psapi.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\xpsp2res.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
				<device_control_communication control_code="0x00390008" count="8" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="3" file="PIPE\lsarpc"/>
			</file_activities>
			<process_activities>
			  <remote_thread_created process="C:\40488567.exe"/>
				<process_killed name="C:\40488567.exe"/>
				<foreign_mem_area_read process="C:\40488567.exe"/>
				<foreign_mem_area_read process="C:\Program Files\Messenger\msmsgs.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\explorer.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\alg.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\cmd.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\csrss.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\ctfmon.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\drwtsn32.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\lsass.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\services.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\smss.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\spoolsv.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\svchost.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\wbem\wmiprvse.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\winlogon.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\wscntfy.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\wuauclt.exe"/>
				<foreign_mem_area_read process="C:\jwsk.exeor.exe"/>
				<foreign_mem_area_read process="C:\sqlk.exeler.exe"/>
				<foreign_mem_area_write process="C:\40488567.exe"/>
			</process_activities>
		</activities>
	</analysis_subject>
	<global_file_info>
	  <global_file info="data" md5="ee0be455c9bffc325aa159aafe9ae689" mimetype="application/octet-stream" name="7E339.dmp" sha1="93282047da94095090d86784bd134f4cd5c676b5"/>
		<global_file info="XML document text" md5="8e2968d96577a86c1a33c91d81dad1f1" mimetype="application/xml" name="b99c_appcompat.txt" sha1="e73d44496dd62f4eea827d8c1135738d3f530cc4"/>
		<global_file info="data" md5="0f56b31365f8927ae4f48362e7d51794" mimetype="application/octet-stream" name="user.dmp" sha1="2f9a8e954a408ecca6125d69d84877e5bc9ac927"/>
		<global_file info="Little-endian UTF-16 Unicode news character data, with CRLF, CR line terminators" md5="706f00d4e0f8e71eb576773778eb2757" mimetype="text/x-news charset=utf-16" name="drwtsn32.log" sha1="ceec167c76e349e575fbbde02b11efbf061b926e"/>
	</global_file_info>
</analysis>
