<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
  <report_version>
	  <major>3</major>
		<minor>2</minor>
	</report_version>
	<configuration>
	  <time_needed>250 s</time_needed>
		<report_created>12/31/11, 04:53:23 UTC</report_created>
		<termination_reason>Timeout</termination_reason>
		<ttanalyze_version>
		  <prog_version>1.75.3394</prog_version>
			<svn_revision>$Revision: 3603 $</svn_revision>
			<build_date>Dec 30 2011 23:19:18</build_date>
		</ttanalyze_version>
	</configuration>
	<summary>
	  <auto_start>true</auto_start>
		<internet_settings>true</internet_settings>
		<bho>false</bho>
		<win_dir_copy>false</win_dir_copy>
		<av_kill>false</av_kill>
		<com_object>false</com_object>
		<dlf>false</dlf>
		<ircbot>false</ircbot>
		<spambot>false</spambot>
		<addressscan>false</addressscan>
		<portscan>false</portscan>
		<file_modification_destruction>true</file_modification_destruction>
		<process_spawn>true</process_spawn>
		<all_reg_activities>true</all_reg_activities>
		<write_to_foreign_mem_area>true</write_to_foreign_mem_area>
		<install_service>false</install_service>
		<load_driver>false</load_driver>
		<install_ie_toolbar>false</install_ie_toolbar>
		<disable_win_update>false</disable_win_update>
		<change_win_firewall_settings>false</change_win_firewall_settings>
		<harvesting_emails>true</harvesting_emails>
		<mod_sys_files>false</mod_sys_files>
		<modify_files_only_in_user_dir>false</modify_files_only_in_user_dir>
		<packed_binary>true</packed_binary>
		<av_hit>false</av_hit>
		<crash>true</crash>
		<autorun>false</autorun>
		<severity_level>6</severity_level>
	</summary>
	<analysis_subject>
	  <general>
		  <id>2</id>
			<parent_id>1</parent_id>
			<analysis_reason>Primary Analysis Subject</analysis_reason>
			<submission_fn>dec8ffd4ea9f368ad11e43dd2e1e58e2.amada</submission_fn>
			<virtual_fn>dec8ffd4ea.exe</virtual_fn>
			<virtual_path>C:\dec8ffd4ea.exe</virtual_path>
			<arguments>"C:\dec8ffd4ea.exe"</arguments>
			<status>dead</status>
			<exit_code>0</exit_code>
			<md5>dec8ffd4ea9f368ad11e43dd2e1e58e2</md5>
			<sha1>7248ea64341dacf1d14ef68c17ce8a10bf131e4b</sha1>
			<file_size>141312</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="1" load_time="1" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="1" load_time="1" size="0x000AA000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00055000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x77B40000" base_name="Apphelp.dll" full_name="C:\WINDOWS\system32\Apphelp.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_key_created name="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="AppData"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="0xa40000000300000037363438372d3634302d313435373233362d32333833" value_name="DigitalProductId"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" value_data="1212451221" value_name="InstallDate"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="AuthenticodeEnabled"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="262144" value_name="DefaultLevel"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="0" value_name="PolicyScope"/>
				<reg_value_read count="2" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0x5eab304f957a49896a006c1c31154015" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="779" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0x67b0d48b343a3fd3bce9dc646704f394" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="517" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0x327802dcfef8c893dc8ab006dd847d1d" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="918" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0xbd9a2adb42ebd8560e250e4df8162f67" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="229" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="32771" value_name="HashAlg"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0x386b085f84ecf669d36b956a22c01e80" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="370" value_name="ItemSize"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK*" value_name="ItemData"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}" value_data="0" value_name="SaferFlags"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files" value_name="Cache"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Application Data" value_name="AppData"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <directory_created name="C:\Documents and Settings\Administrator\Application Data\Abbi"/>
				<directory_created name="C:\Documents and Settings\Administrator\Application Data\Yldyl"/>
				<file_created name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp82436790.bat"/>
				<file_created name="C:\Documents and Settings\Administrator\Application Data\Abbi"/>
				<file_created name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.awd"/>
				<file_created name="C:\Documents and Settings\Administrator\Application Data\Yldyl"/>
				<file_created name="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<file_modified name="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp82436790.bat"/>
				<file_modified name="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<file_modified name="MountPointManager"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\dec8ffd4ea.exe"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\Apphelp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\cmd.exe" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
				<fs_control_communication control_code="0x00090028" count="1" file="C:\Program Files\Common Files\"/>
				<device_control_communication control_code="0x00390008" count="1" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="15" file="PIPE\lsarpc"/>
				<device_control_communication control_code="0x004D0008" count="2" file="C:"/>
				<device_control_communication control_code="0x006D0008" count="2" file="MountPointManager"/>
			</file_activities>
			<process_activities>
			  <remote_thread_created process="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<remote_thread_created process="C:\WINDOWS\system32\cmd.exe"/>
				<foreign_mem_area_read process="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<foreign_mem_area_read process="C:\WINDOWS\system32\cmd.exe"/>
				<foreign_mem_area_write process="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<foreign_mem_area_write process="C:\WINDOWS\system32\cmd.exe"/>
				<process_created cmd_line="" description="process_spawn" exe_name="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<process_created cmd_line="&quot;C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe&quot;" description="process_spawn" exe_name=""/>
				<process_created cmd_line="" description="process_spawn" exe_name="C:\WINDOWS\system32\cmd.exe"/>
				<process_created cmd_line="&quot;C:\WINDOWS\system32\cmd.exe&quot; /c &quot;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp82436790.bat&quot;" description="process_spawn" exe_name=""/>
			</process_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>3</id>
			<parent_id>2</parent_id>
			<analysis_reason>Started by dec8ffd4ea.exe</analysis_reason>
			<virtual_fn>olne.exe</virtual_fn>
			<virtual_path>C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe</virtual_path>
			<arguments>"C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"</arguments>
			<status>dead</status>
			<exit_code>0</exit_code>
			<md5>8ed8abfaee8bd928a03d56b563f76f59</md5>
			<sha1>249133273ae1a3d3cfb725c571975ee829cbb5b7</sha1>
			<file_size>141312</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="1" load_time="1" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="1" load_time="1" size="0x000AA000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00055000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="AppData"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Application Data" value_name="AppData"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="MountPointManager"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
				<fs_control_communication control_code="0x00090028" count="1" file="C:\Documents and Settings\Administrator\Application Data"/>
				<device_control_communication control_code="0x00390008" count="1" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="4" file="PIPE\lsarpc"/>
				<device_control_communication control_code="0x004D0008" count="1" file="C:"/>
				<device_control_communication control_code="0x006D0008" count="1" file="MountPointManager"/>
			</file_activities>
			<process_activities>
			  <remote_thread_created process="C:\WINDOWS\explorer.exe"/>
				<remote_thread_created process="C:\WINDOWS\system32\ctfmon.exe"/>
				<remote_thread_created process="C:\Program Files\Messenger\msmsgs.exe"/>
				<remote_thread_created process="C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe"/>
				<remote_thread_created process="C:\Program Files\Common Files\kxuckd.exe"/>
				<remote_thread_created process="C:\Program Files\Common Files\drlwszvxbeo.exe"/>
				<remote_thread_created process="C:\dec8ffd4ea.exe"/>
				<foreign_mem_area_write process="C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe"/>
				<foreign_mem_area_write process="C:\Program Files\Common Files\drlwszvxbeo.exe"/>
				<foreign_mem_area_write process="C:\Program Files\Common Files\kxuckd.exe"/>
				<foreign_mem_area_write process="C:\Program Files\Messenger\msmsgs.exe"/>
				<foreign_mem_area_write process="C:\WINDOWS\explorer.exe"/>
				<foreign_mem_area_write process="C:\WINDOWS\system32\ctfmon.exe"/>
				<foreign_mem_area_write process="C:\dec8ffd4ea.exe"/>
			</process_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>4</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>Explorer.EXE</virtual_fn>
			<virtual_path>C:\WINDOWS\Explorer.EXE</virtual_path>
			<arguments>C:\WINDOWS\Explorer.EXE</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>12896823fb95bfb3dc9b46bcaedc9923</md5>
			<sha1>9d2bf84874abc5b6e9a2744b7865c193c08d362f</sha1>
			<file_size>1033728</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x75F80000" base_name="BROWSEUI.dll" full_name="C:\WINDOWS\system32\BROWSEUI.dll" is_load_time_dependency="1" load_time="1" size="0x000FD000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x7E290000" base_name="SHDOCVW.dll" full_name="C:\WINDOWS\system32\SHDOCVW.dll" is_load_time_dependency="1" load_time="1" size="0x00171000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="1" load_time="1" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x754D0000" base_name="CRYPTUI.dll" full_name="C:\WINDOWS\system32\CRYPTUI.dll" is_load_time_dependency="1" load_time="1" size="0x00080000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00055000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="1" load_time="1" size="0x000AA000"/>
			<loaded_dll base_address="0x76C30000" base_name="WINTRUST.dll" full_name="C:\WINDOWS\system32\WINTRUST.dll" is_load_time_dependency="1" load_time="1" size="0x0002E000"/>
			<loaded_dll base_address="0x76C90000" base_name="IMAGEHLP.dll" full_name="C:\WINDOWS\system32\IMAGEHLP.dll" is_load_time_dependency="1" load_time="1" size="0x00028000"/>
			<loaded_dll base_address="0x76F60000" base_name="WLDAP32.dll" full_name="C:\WINDOWS\system32\WLDAP32.dll" is_load_time_dependency="1" load_time="1" size="0x0002C000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x5AD70000" base_name="UxTheme.dll" full_name="C:\WINDOWS\system32\UxTheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
			<loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
			<loaded_dll base_address="0x6F880000" base_name="AcGenral.DLL" full_name="C:\WINDOWS\AppPatch\AcGenral.DLL" is_load_time_dependency="1" load_time="1" size="0x001CA000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x77BE0000" base_name="MSACM32.dll" full_name="C:\WINDOWS\system32\MSACM32.dll" is_load_time_dependency="1" load_time="1" size="0x00015000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x77B40000" base_name="appHelp.dll" full_name="C:\WINDOWS\system32\appHelp.dll" is_load_time_dependency="1" load_time="1" size="0x00022000"/>
			<loaded_dll base_address="0x76FD0000" base_name="CLBCATQ.DLL" full_name="C:\WINDOWS\system32\CLBCATQ.DLL" is_load_time_dependency="1" load_time="1" size="0x0007F000"/>
			<loaded_dll base_address="0x77050000" base_name="COMRes.dll" full_name="C:\WINDOWS\system32\COMRes.dll" is_load_time_dependency="1" load_time="1" size="0x000C5000"/>
			<loaded_dll base_address="0x77A20000" base_name="cscui.dll" full_name="C:\WINDOWS\System32\cscui.dll" is_load_time_dependency="1" load_time="1" size="0x00054000"/>
			<loaded_dll base_address="0x76600000" base_name="CSCDLL.dll" full_name="C:\WINDOWS\System32\CSCDLL.dll" is_load_time_dependency="1" load_time="1" size="0x0001D000"/>
			<loaded_dll base_address="0x5BA60000" base_name="themeui.dll" full_name="C:\WINDOWS\system32\themeui.dll" is_load_time_dependency="1" load_time="1" size="0x00071000"/>
			<loaded_dll base_address="0x76380000" base_name="MSIMG32.dll" full_name="C:\WINDOWS\system32\MSIMG32.dll" is_load_time_dependency="1" load_time="1" size="0x00005000"/>
			<loaded_dll base_address="0x00AC0000" base_name="xpsp2res.dll" full_name="C:\WINDOWS\system32\xpsp2res.dll" is_load_time_dependency="1" load_time="1" size="0x002C5000"/>
			<loaded_dll base_address="0x71D40000" base_name="actxprxy.dll" full_name="C:\WINDOWS\system32\actxprxy.dll" is_load_time_dependency="1" load_time="1" size="0x0001B000"/>
			<loaded_dll base_address="0x5FC10000" base_name="msutb.dll" full_name="C:\WINDOWS\system32\msutb.dll" is_load_time_dependency="1" load_time="1" size="0x00033000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x7E1E0000" base_name="urlmon.dll" full_name="C:\WINDOWS\system32\urlmon.dll" is_load_time_dependency="1" load_time="1" size="0x000A2000"/>
			<loaded_dll base_address="0x76980000" base_name="LINKINFO.dll" full_name="C:\WINDOWS\system32\LINKINFO.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76990000" base_name="ntshrui.dll" full_name="C:\WINDOWS\system32\ntshrui.dll" is_load_time_dependency="1" load_time="1" size="0x00025000"/>
			<loaded_dll base_address="0x76B20000" base_name="ATL.DLL" full_name="C:\WINDOWS\system32\ATL.DLL" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x68000000" base_name="rsaenh.dll" full_name="C:\WINDOWS\system32\rsaenh.dll" is_load_time_dependency="1" load_time="1" size="0x00036000"/>
			<loaded_dll base_address="0x7D1E0000" base_name="msi.dll" full_name="C:\WINDOWS\system32\msi.dll" is_load_time_dependency="1" load_time="1" size="0x002BC000"/>
			<loaded_dll base_address="0x76360000" base_name="WINSTA.dll" full_name="C:\WINDOWS\system32\WINSTA.dll" is_load_time_dependency="1" load_time="1" size="0x00010000"/>
			<loaded_dll base_address="0x74B30000" base_name="webcheck.dll" full_name="C:\WINDOWS\system32\webcheck.dll" is_load_time_dependency="1" load_time="1" size="0x00046000"/>
			<loaded_dll base_address="0x71AD0000" base_name="WSOCK32.dll" full_name="C:\WINDOWS\system32\WSOCK32.dll" is_load_time_dependency="1" load_time="1" size="0x00009000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76280000" base_name="stobject.dll" full_name="C:\WINDOWS\system32\stobject.dll" is_load_time_dependency="1" load_time="1" size="0x00021000"/>
			<loaded_dll base_address="0x74AF0000" base_name="BatMeter.dll" full_name="C:\WINDOWS\system32\BatMeter.dll" is_load_time_dependency="1" load_time="1" size="0x0000A000"/>
			<loaded_dll base_address="0x74AD0000" base_name="POWRPROF.dll" full_name="C:\WINDOWS\system32\POWRPROF.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x77920000" base_name="SETUPAPI.dll" full_name="C:\WINDOWS\system32\SETUPAPI.dll" is_load_time_dependency="1" load_time="1" size="0x000F3000"/>
			<loaded_dll base_address="0x76F50000" base_name="WTSAPI32.dll" full_name="C:\WINDOWS\system32\WTSAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76400000" base_name="NETSHELL.dll" full_name="C:\WINDOWS\system32\NETSHELL.dll" is_load_time_dependency="1" load_time="1" size="0x001A5000"/>
			<loaded_dll base_address="0x76C00000" base_name="credui.dll" full_name="C:\WINDOWS\system32\credui.dll" is_load_time_dependency="1" load_time="1" size="0x0002E000"/>
			<loaded_dll base_address="0x478C0000" base_name="dot3api.dll" full_name="C:\WINDOWS\system32\dot3api.dll" is_load_time_dependency="1" load_time="1" size="0x0000A000"/>
			<loaded_dll base_address="0x76E80000" base_name="rtutils.dll" full_name="C:\WINDOWS\system32\rtutils.dll" is_load_time_dependency="1" load_time="1" size="0x0000E000"/>
			<loaded_dll base_address="0x736D0000" base_name="dot3dlg.dll" full_name="C:\WINDOWS\system32\dot3dlg.dll" is_load_time_dependency="1" load_time="1" size="0x00006000"/>
			<loaded_dll base_address="0x5DCA0000" base_name="OneX.DLL" full_name="C:\WINDOWS\system32\OneX.DLL" is_load_time_dependency="1" load_time="1" size="0x00028000"/>
			<loaded_dll base_address="0x745B0000" base_name="eappcfg.dll" full_name="C:\WINDOWS\system32\eappcfg.dll" is_load_time_dependency="1" load_time="1" size="0x00022000"/>
			<loaded_dll base_address="0x76080000" base_name="MSVCP60.dll" full_name="C:\WINDOWS\system32\MSVCP60.dll" is_load_time_dependency="1" load_time="1" size="0x00065000"/>
			<loaded_dll base_address="0x5DCD0000" base_name="eappprxy.dll" full_name="C:\WINDOWS\system32\eappprxy.dll" is_load_time_dependency="1" load_time="1" size="0x0000E000"/>
			<loaded_dll base_address="0x76D60000" base_name="iphlpapi.dll" full_name="C:\WINDOWS\system32\iphlpapi.dll" is_load_time_dependency="1" load_time="1" size="0x00019000"/>
			<loaded_dll base_address="0x71B20000" base_name="MPR.dll" full_name="C:\WINDOWS\system32\MPR.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x75F60000" base_name="drprov.dll" full_name="C:\WINDOWS\System32\drprov.dll" is_load_time_dependency="1" load_time="1" size="0x00007000"/>
			<loaded_dll base_address="0x71C10000" base_name="ntlanman.dll" full_name="C:\WINDOWS\System32\ntlanman.dll" is_load_time_dependency="1" load_time="1" size="0x0000E000"/>
			<loaded_dll base_address="0x71CD0000" base_name="NETUI0.dll" full_name="C:\WINDOWS\System32\NETUI0.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71C90000" base_name="NETUI1.dll" full_name="C:\WINDOWS\System32\NETUI1.dll" is_load_time_dependency="1" load_time="1" size="0x00040000"/>
			<loaded_dll base_address="0x71C80000" base_name="NETRAP.dll" full_name="C:\WINDOWS\System32\NETRAP.dll" is_load_time_dependency="1" load_time="1" size="0x00007000"/>
			<loaded_dll base_address="0x71BF0000" base_name="SAMLIB.dll" full_name="C:\WINDOWS\System32\SAMLIB.dll" is_load_time_dependency="1" load_time="1" size="0x00013000"/>
			<loaded_dll base_address="0x75F70000" base_name="davclnt.dll" full_name="C:\WINDOWS\System32\davclnt.dll" is_load_time_dependency="1" load_time="1" size="0x0000A000"/>
			<loaded_dll base_address="0x763B0000" base_name="comdlg32.dll" full_name="C:\WINDOWS\system32\comdlg32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x75970000" base_name="MSGINA.dll" full_name="C:\WINDOWS\system32\MSGINA.dll" is_load_time_dependency="1" load_time="1" size="0x000F8000"/>
			<loaded_dll base_address="0x74320000" base_name="ODBC32.dll" full_name="C:\WINDOWS\system32\ODBC32.dll" is_load_time_dependency="1" load_time="1" size="0x0003D000"/>
			<loaded_dll base_address="0x01350000" base_name="odbcint.dll" full_name="C:\WINDOWS\system32\odbcint.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71600000" base_name="browselc.dll" full_name="C:\WINDOWS\system32\browselc.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x71800000" base_name="shdoclc.dll" full_name="C:\WINDOWS\system32\shdoclc.dll" is_load_time_dependency="1" load_time="1" size="0x00088000"/>
			<loaded_dll base_address="0x02380000" base_name="inetres.dll" full_name="C:\WINDOWS\system32\inetres.dll" is_load_time_dependency="0" load_time="2" size="0x0000E000"/>
			<loaded_dll base_address="0x023D0000" base_name="msoeres.dll" full_name="C:\Program Files\Outlook Express\msoeres.dll" is_load_time_dependency="0" load_time="2" size="0x0025F000"/>
			<loaded_dll base_address="0x35F40000" base_name="wab32res.dll" full_name="C:\Program Files\Common Files\System\wab32res.dll" is_load_time_dependency="0" load_time="2" size="0x0003F000"/>
			<loaded_dll base_address="0x470D0000" base_name="wab32.dll" full_name="C:\Program Files\Common Files\System\wab32.dll" is_load_time_dependency="0" load_time="2" size="0x00081000"/>
			<loaded_dll base_address="0x5E0C0000" base_name="PSTOREC.DLL" full_name="C:\WINDOWS\system32\PSTOREC.DLL" is_load_time_dependency="0" load_time="2" size="0x0000D000"/>
			<loaded_dll base_address="0x60330000" base_name="msoe.dll" full_name="C:\Program Files\Outlook Express\msoe.dll" is_load_time_dependency="0" load_time="2" size="0x00148000"/>
			<loaded_dll base_address="0x60890000" base_name="msidntld.dll" full_name="C:\WINDOWS\system32\msidntld.dll" is_load_time_dependency="0" load_time="2" size="0x00006000"/>
			<loaded_dll base_address="0x608A0000" base_name="msident.dll" full_name="C:\WINDOWS\system32\msident.dll" is_load_time_dependency="0" load_time="2" size="0x0000F000"/>
			<loaded_dll base_address="0x662B0000" base_name="hnetcfg.dll" full_name="C:\WINDOWS\system32\hnetcfg.dll" is_load_time_dependency="0" load_time="2" size="0x00058000"/>
			<loaded_dll base_address="0x68810000" base_name="msoeacct.dll" full_name="C:\WINDOWS\system32\msoeacct.dll" is_load_time_dependency="0" load_time="2" size="0x00042000"/>
			<loaded_dll base_address="0x6CDF0000" base_name="directdb.dll" full_name="C:\Program Files\Common Files\System\directdb.dll" is_load_time_dependency="0" load_time="2" size="0x00019000"/>
			<loaded_dll base_address="0x71780000" base_name="acctres.dll" full_name="C:\WINDOWS\system32\acctres.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
			<loaded_dll base_address="0x71A50000" base_name="mswsock.dll" full_name="C:\WINDOWS\system32\mswsock.dll" is_load_time_dependency="0" load_time="2" size="0x0003F000"/>
			<loaded_dll base_address="0x71A90000" base_name="wshtcpip.dll" full_name="C:\WINDOWS\System32\wshtcpip.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x722B0000" base_name="sensapi.dll" full_name="C:\WINDOWS\system32\sensapi.dll" is_load_time_dependency="0" load_time="2" size="0x00005000"/>
			<loaded_dll base_address="0x75CF0000" base_name="mlang.dll" full_name="C:\WINDOWS\system32\mlang.dll" is_load_time_dependency="0" load_time="2" size="0x00091000"/>
			<loaded_dll base_address="0x76150000" base_name="INETCOMM.dll" full_name="C:\WINDOWS\system32\INETCOMM.dll" is_load_time_dependency="0" load_time="2" size="0x000AE000"/>
			<loaded_dll base_address="0x76880000" base_name="MSOERT2.dll" full_name="C:\WINDOWS\system32\MSOERT2.dll" is_load_time_dependency="0" load_time="2" size="0x00022000"/>
			<loaded_dll base_address="0x76E90000" base_name="rasman.dll" full_name="C:\WINDOWS\system32\rasman.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
			<loaded_dll base_address="0x76EB0000" base_name="TAPI32.dll" full_name="C:\WINDOWS\system32\TAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x0002F000"/>
			<loaded_dll base_address="0x76EE0000" base_name="RASAPI32.DLL" full_name="C:\WINDOWS\system32\RASAPI32.DLL" is_load_time_dependency="0" load_time="2" size="0x0003C000"/>
			<loaded_dll base_address="0x76F20000" base_name="DNSAPI.dll" full_name="C:\WINDOWS\system32\DNSAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00027000"/>
			<loaded_dll base_address="0x76FC0000" base_name="rasadhlp.dll" full_name="C:\WINDOWS\system32\rasadhlp.dll" is_load_time_dependency="0" load_time="2" size="0x00006000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_key_created name="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy"/>
				<reg_value_modified count="1" description="internet_settings" key="HKLM\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_modified count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\All Users\Application Data" value_name="Common AppData"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="622675" value_name="Identity Login"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="2" value_name="Identity Ordinal"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="{42D8066E-F069-48E2-9549-21646EC1BC68}" value_name="Last User ID"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="Main Identity" value_name="Last Username"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="2" value_name="Compact Check Count"/>
				<reg_value_modified count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="0" value_name="Running"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="7" value_name="Settings Upgraded"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="1" value_name="StoreMigratedV5"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0\Mail" value_data="28591" value_name="Default_CodePage"/>
				<reg_value_modified count="1" description="auto_start" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN" value_data="&quot;C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe&quot;" value_name="{C635B4FE-FC1B-0929-C8B9-195C641AE08E}"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0x76a5d88fa712d496f07bdcb637a2bb8bb0bc54a39260b46ed49c39e579b4" value_name="Actig"/>
				<reg_value_modified count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_modified count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager" value_data="4" value_name="Server ID"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts" value_data="0x6e06d84269f0e248954921646ec1bc68" value_name="AssociatedID"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts" value_data="1" value_name="ConnectionSettingsMigrated"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="1" value_name="FirstRun"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="0" value_name="OlkContactRefresh"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="0" value_name="OlkFolderRefresh"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="AppData"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\UnreadMail\john.ramo@seclab.tuwien.ac.at" value_data="msimn" value_name="Application"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\UnreadMail\john.ramo@seclab.tuwien.ac.at" value_data="0" value_name="MessageCount"/>
				<reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\UnreadMail\john.ramo@seclab.tuwien.ac.at" value_data="0x268b86db31d9cb01" value_name="TimeStamp"/>
				<reg_value_modified count="164" description="auto_start" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\Currentversion\Run" value_data="&quot;C:\Documents and Settings\Administrator\Application Data\Yldyl\olne.exe&quot;" value_name="{C635B4FE-FC1B-0929-C8B9-195C641AE08E}"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000001600000001000000000000000000000000000000040000000000" value_name="SavedLegacySettings"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\INPROCSERVER32" value_data="C:\WINDOWS\system32\mlang.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{4A16043F-676D-11D2-994E-00C04FA309D4}\INPROCSERVER32" value_data="%ProgramFiles%\Common Files\System\directdb.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{4A16043F-676D-11D2-994E-00C04FA309D4}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="3" key="HKLM\SOFTWARE\CLASSES\CLSID\{8D4B04E1-1331-11D0-81B8-00C04FD85AB4}\INPROCSERVER32" value_data="%SystemRoot%\system32\msoeacct.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{8D4B04E1-1331-11D0-81B8-00C04FD85AB4}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="4" key="HKLM\SOFTWARE\CLASSES\CLSID\{A9AE6C91-1D1B-11D2-B21A-00C04FA357FA}\INPROCSERVER32" value_data="C:\WINDOWS\system32\msident.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{A9AE6C91-1D1B-11D2-B21A-00C04FA357FA}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\CLSID\{B0D17FC2-7BC4-11D1-BDFA-00C04FA31009}\INPROCSERVER32" value_data="%SystemRoot%\system32\inetcomm.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{B0D17FC2-7BC4-11D1-BDFA-00C04FA31009}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\CLSID\{E70C92A9-4BFD-11D1-8A95-00C04FB951F3}\INPROCSERVER32" value_data="%ProgramFiles%\Outlook Express\msoe.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{E70C92A9-4BFD-11D1-8A95-00C04FB951F3}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{FD853CDD-7F86-11D0-8252-00C04FD85AB4}\INPROCSERVER32" value_data="%SystemRoot%\system32\inetcomm.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{FD853CDD-7F86-11D0-8252-00C04FD85AB4}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="4" key="HKLM\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\TEXT/HTML" value_data=".htm" value_name="Extension"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="4294901760" value_name="ConsoleTracingMask"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="0" value_name="EnableConsoleTracing"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="0" value_name="EnableFileTracing"/>
				<reg_value_read count="4" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="%windir%\tracing" value_name="FileDirectory"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="4294901760" value_name="FileTracingMask"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" value_data="1048576" value_name="MaxFileSize"/>
				<reg_value_read count="44" key="HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001" value_data="Microsoft Strong Cryptographic Provider" value_name="Name"/>
				<reg_value_read count="44" key="HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider" value_data="rsaenh.dll" value_name="Image Path"/>
				<reg_value_read count="11" key="HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider" value_data="1" value_name="Type"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\WAB\DLLPath" value_data="C:\Program Files\Common Files\System\wab32.dll" value_name=""/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0x00000000" value_name="UrlEncoding"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET CLR 1.1.4322"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET CLR 2.0.50727"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET CLR 3.0.04506.30"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET CLR 3.0.04506.648"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET CLR 3.5.21022"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET4.0C"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform" value_data="" value_name=".NET4.0E"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform" value_data="" value_name="SV1"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens" value_data="" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens" value_data="" value_name="MSN 2.0"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens" value_data="" value_name="MSN 2.5"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="%SystemRoot%\system32\cmd.exe" value_name="ComSpec"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="NO" value_name="FP_NO_HOST_CHECK"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="1" value_name="NUMBER_OF_PROCESSORS"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="Windows_NT" value_name="OS"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH" value_name="PATHEXT"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="x86" value_name="PROCESSOR_ARCHITECTURE"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="x86 Family 6 Model 3 Stepping 3, GenuineIntel" value_name="PROCESSOR_IDENTIFIER"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="6" value_name="PROCESSOR_LEVEL"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="0303" value_name="PROCESSOR_REVISION"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem" value_name="Path"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="%SystemRoot%\TEMP" value_name="TEMP"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="%SystemRoot%\TEMP" value_name="TMP"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER\ENVIRONMENT" value_data="%SystemRoot%" value_name="windir"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders" value_data="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" value_name="SecurityProviders"/>
				<reg_value_read count="2" key="HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters" value_data="0x5400630070006900700000004e0065007400420049004f00530000000000" value_name="Transports"/>
				<reg_value_read count="1" key="HKLM\Software\Clients\IM\Windows Messenger\InstallInfo" value_data="1" value_name="IconsVisible"/>
				<reg_value_read count="28" key="HKLM\Software\Microsoft\COM3" value_data="0x0b00000000000000" value_name="REGDBVersion"/>
				<reg_value_read count="44" key="HKLM\Software\Microsoft\Cryptography" value_data="4604e8cc-5b9c-4ffb-a374-a62e6d0494fc" value_name="MachineGuid"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16" value_data="cryptnet.dll" value_name="Dll"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16" value_data="LdapProvOpenStore" value_name="FuncName"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap" value_data="cryptnet.dll" value_name="Dll"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap" value_data="LdapProvOpenStore" value_name="FuncName"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Internet Account Manager\Preconfigured" value_data="4" value_name="PreConfigVer"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Internet Account Manager\Preconfigured" value_data="1" value_name="PreConfigVerNTDS"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING" value_data="1" value_name="Explorer.EXE"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Outlook Express\5.0\Required Settings" value_data="3" value_name="VerStamp"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="ConsoleTracingMask"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableConsoleTracing"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableFileTracing"/>
				<reg_value_read count="6" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="%windir%\tracing" value_name="FileDirectory"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="FileTracingMask"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="1048576" value_name="MaxFileSize"/>
				<reg_value_read count="7" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes" value_data="Microsoft Sans Serif" value_name="MS Shell Dlg"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="All Users" value_name="AllUsersProfile"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="Default User" value_name="DefaultUserProfile"/>
				<reg_value_read count="8" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="%SystemDrive%\Documents and Settings" value_name="ProfilesDirectory"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-1425521274-308236825-500" value_data="%SystemDrive%\Documents and Settings\Administrator" value_name="ProfileImagePath"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files\Common Files" value_name="CommonFilesDir"/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files" value_name="ProgramFilesDir"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%ALLUSERSPROFILE%\Application Data" value_name="Common AppData"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10000.nls" value_name="10000"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10001"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10002"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10003"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10004"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10005"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10006.nls" value_name="10006"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10007.nls" value_name="10007"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10008"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10010.nls" value_name="10010"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10017.nls" value_name="10017"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="10021"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10029.nls" value_name="10029"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10079.nls" value_name="10079"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10081.nls" value_name="10081"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_10082.nls" value_name="10082"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1026.nls" value_name="1026"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1047"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1140"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1141"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1142"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1143"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1144"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1145"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1146"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1147"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1148"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="1149"/>
				<reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1250.nls" value_name="1250"/>
				<reg_value_read count="14" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1251.nls" value_name="1251"/>
				<reg_value_read count="11" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1253.nls" value_name="1253"/>
				<reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1254.nls" value_name="1254"/>
				<reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1255.nls" value_name="1255"/>
				<reg_value_read count="13" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1256.nls" value_name="1256"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1257.nls" value_name="1257"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1258.nls" value_name="1258"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_1361.nls" value_name="1361"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20000"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20001"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20002"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20003"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20004"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20005"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20105"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20106"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20107"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20108"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_20127.nls" value_name="20127"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_20261.nls" value_name="20261"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20269"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20273"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20277"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20278"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20280"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20284"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20285"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20290"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20297"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20420"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20423"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20424"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20833"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20838"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_20866.nls" value_name="20866"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20871"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20880"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20905"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20924"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20932"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20936"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="20949"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="21025"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="21027"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_21866.nls" value_name="21866"/>
				<reg_value_read count="3" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="C_28591.NLS" value_name="28591"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="C_28592.NLS" value_name="28592"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="28593"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="C_28594.NLS" value_name="28594"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="C_28595.NLS" value_name="28595"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="28596"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="C_28597.NLS" value_name="28597"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="28598"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_28599.nls" value_name="28599"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_28603.nls" value_name="28603"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_28605.nls" value_name="28605"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_037.nls" value_name="37"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="38598"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_437.nls" value_name="437"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_500.nls" value_name="500"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50220"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50221"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50222"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50225"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50227"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="50229"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="51949"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="52936"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57002"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57003"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57004"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57005"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57006"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57007"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57008"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57009"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57010"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="57011"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="708"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="720"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_737.nls" value_name="737"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_775.nls" value_name="775"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_852.nls" value_name="852"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_855.nls" value_name="855"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_857.nls" value_name="857"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="858"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_860.nls" value_name="860"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_861.nls" value_name="861"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="862"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_863.nls" value_name="863"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="864"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_865.nls" value_name="865"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_866.nls" value_name="866"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_869.nls" value_name="869"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="" value_name="870"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_874.nls" value_name="874"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_875.nls" value_name="875"/>
				<reg_value_read count="20" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_932.nls" value_name="932"/>
				<reg_value_read count="14" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_936.nls" value_name="936"/>
				<reg_value_read count="16" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_949.nls" value_name="949"/>
				<reg_value_read count="13" key="HKLM\System\CurrentControlSet\Control\Nls\Codepage" value_data="c_950.nls" value_name="950"/>
				<reg_value_read count="7" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32\cmd.exe" value_name="ComSpec"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="NO" value_name="FP_NO_HOST_CHECK"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="1" value_name="NUMBER_OF_PROCESSORS"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="Windows_NT" value_name="OS"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH" value_name="PATHEXT"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86" value_name="PROCESSOR_ARCHITECTURE"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86 Family 6 Model 3 Stepping 3, GenuineIntel" value_name="PROCESSOR_IDENTIFIER"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="6" value_name="PROCESSOR_LEVEL"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="0303" value_name="PROCESSOR_REVISION"/>
				<reg_value_read count="7" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem" value_name="Path"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TEMP"/>
				<reg_value_read count="6" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TMP"/>
				<reg_value_read count="7" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%" value_name="windir"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="" value_name="Domain"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="pc" value_name="Hostname"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="0" value_name="UseDomainNameDevolution"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="%SystemRoot%\System32\wshtcpip.dll" value_name="HelperDllName"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="0x0b0000000300000002000000010000000600000002000000010000000000" value_name="Mapping"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="16" value_name="MaxSockaddrLength"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="16" value_name="MinSockaddrLength"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="0" value_name="UseDelayedAcceptance"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TEMP"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TMP"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="{42D8066E-F069-48E2-9549-21646EC1BC68}" value_name="Default User ID"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="2" value_name="Identity Ordinal"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities" value_data="1" value_name="Migrated5"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}" value_data="1" value_name="Identity Ordinal"/>
				<reg_value_read count="16" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}" value_data="{42D8066E-F069-48E2-9549-21646EC1BC68}" value_name="User ID"/>
				<reg_value_read count="18" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}" value_data="Main Identity" value_name="Username"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="1" value_name="Compact Check Count"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="1" value_name="ConvertedToDBX"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="1" value_name="MSIMN"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="0" value_name="Running"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="7" value_name="Settings Upgraded"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="0x2c0000000000000001000000ffffffffffffffffffffffffffffffff9c00" value_name="SpoolerDlgPos"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="0" value_name="SpoolerTack"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="%UserProfile%\Local Settings\Application Data\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Microsoft\Outlook Express\" value_name="Store Root"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="1" value_name="StoreMigratedV5"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0" value_data="3" value_name="VerStamp"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0\Mail" value_data="28591" value_name="Default_CodePage"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Software\Microsoft\Outlook Express\5.0\mail" value_data="1" value_name="Secure Safe Attachments"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="1" value_name="EnableNegotiate"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="multipart/mixed multipart/x-mixed-replace multipart/x-byteranges " value_name="MimeExclusionListForCache"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="0x01000000" value_name="WarnOnPost"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="1" value_name="EnableHttp1_1"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="Mozilla/4.0 (compatible; MSIE 6.0; Win32)" value_name="User Agent"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0x76a5d88fa712d496f07bdcb637a2bb8bb0bc54a39260b46ed49c39e579b4" value_name="Actig"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager" value_data="Active Directory GC" value_name="Default LDAP Account"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager" value_data="00000001" value_name="Default Mail Account"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts" value_data="0x6e06d84269f0e248954921646ec1bc68" value_name="AssociatedID"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts" value_data="4" value_name="PreConfigVer"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts" value_data="1" value_name="PreConfigVerNTDS"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="pop.rambo.com" value_name="Account Name"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="3" value_name="Connection Type"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="1" value_name="POP3 Prompt for Password"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="pop.rambo.com" value_name="POP3 Server"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="1" value_name="POP3 Skip Account"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="0" value_name="POP3 Use Sicily"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="john.ramo" value_name="POP3 User Name"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="John Walker" value_name="SMTP Display Name"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="john.ramo@seclab.tuwien.ac.at" value_name="SMTP Email Address"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\00000001" value_data="seclab.tuwien.ac.at" value_name="SMTP Server"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="Active Directory" value_name="Account Name"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="2" value_name="LDAP Authentication"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="0" value_name="LDAP Bind DN"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="3268" value_name="LDAP Port"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="1" value_name="LDAP Resolve Flag"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="NULL" value_name="LDAP Search Base"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="100" value_name="LDAP Search Return"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="0" value_name="LDAP Secure Connection"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="NULL" value_name="LDAP Server"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="0" value_name="LDAP Server ID"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="0" value_name="LDAP Simple Search"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="60" value_name="LDAP Timeout"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC" value_data="NULL" value_name="LDAP User Name"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="Bigfoot Internet Directory Service" value_name="Account Name"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="0" value_name="LDAP Authentication"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="%ProgramFiles%\Common Files\Services\bigfoot.bmp" value_name="LDAP Logo"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="100" value_name="LDAP Search Return"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="ldap.bigfoot.com" value_name="LDAP Server"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="1" value_name="LDAP Server ID"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="1" value_name="LDAP Simple Search"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="60" value_name="LDAP Timeout"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot" value_data="http://www.bigfoot.com" value_name="LDAP URL"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="VeriSign Internet Directory Service" value_name="Account Name"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="0" value_name="LDAP Authentication"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="%ProgramFiles%\Common Files\Services\verisign.bmp" value_name="LDAP Logo"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="NULL" value_name="LDAP Search Base"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="100" value_name="LDAP Search Return"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="directory.verisign.com" value_name="LDAP Server"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="2" value_name="LDAP Server ID"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="1" value_name="LDAP Simple Search"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="60" value_name="LDAP Timeout"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\VeriSign" value_data="http://www.verisign.com" value_name="LDAP URL"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="WhoWhere Internet Directory Service" value_name="Account Name"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="0" value_name="LDAP Authentication"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="%ProgramFiles%\Common Files\Services\whowhere.bmp" value_name="LDAP Logo"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="100" value_name="LDAP Search Return"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="ldap.whowhere.com" value_name="LDAP Server"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="3" value_name="LDAP Server ID"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="1" value_name="LDAP Simple Search"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="60" value_name="LDAP Timeout"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere" value_data="http://www.whowhere.com" value_name="LDAP URL"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="1" value_name="FirstRun"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="0" value_name="OlkContactRefresh"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4" value_data="0" value_name="OlkFolderRefresh"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\WAB\WAB4\Wab File Name" value_data="C:\Documents and Settings\Administrator\Application Data\Microsoft\Address Book\Administrator.wab" value_name=""/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" value_data="1" value_name="ParseAutoexec"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="AppData"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Application Data" value_name="AppData"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\" value_data="1" value_name="IntranetName"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\" value_data="1" value_name="ProxyBypass"/>
				<reg_value_read count="3" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\" value_data="3" value_name="http"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="1" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="1" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="1" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="1" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="3" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="1" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="1" value_name="1A10"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0x1a3761592352350c7a5f20172f1e1a190e2b01731e281a041b0c3bc22127" value_name="{AEBA21FA-782A-4A90-978D-B72164C80120}"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="3" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="1" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000000300000001000000000000000000000000000000040000000000" value_name="DefaultConnectionSettings"/>
				<reg_value_read count="4" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000001500000001000000000000000000000000000000040000000000" value_name="SavedLegacySettings"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="C:\Documents and Settings\Administrator\Application Data" value_name="APPDATA"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="Console" value_name="CLIENTNAME"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="C:" value_name="HOMEDRIVE"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="\Documents and Settings\Administrator" value_name="HOMEPATH"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="" value_name="HOMESHARE"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="\\PC" value_name="LOGONSERVER"/>
				<reg_value_read count="8" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment" value_data="Console" value_name="SESSIONNAME"/>
				<reg_key_monitored count="2" key="HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL" notify_filter="Attributes Change,Value Change,Security Descriptor Change" watch_subtree="0"/>
				<reg_key_monitored count="3" key="HKLM\Software\Microsoft\Tracing\RASAPI32" notify_filter="Attributes Change,Value Change,Security Descriptor Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="6" key="HKU" notify_filter="Key Change,Value Change" watch_subtree="1"/>
			</registry_activities>
			<file_activities>
			  <file_created name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.awd"/>
				<file_created name="C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt"/>
				<file_created name="C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt"/>
				<file_created name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\config[1].bin"/>
				<file_created name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\gate[1].htm"/>
				<file_created name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\webhp[1].htm"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.tmp"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt"/>
				<file_deleted name="C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Cookies\administrator@java[1].txt"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Cookies\administrator@promotion.adobe[1].txt"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Cookies\administrator@sun[1].txt"/>
				<file_deleted description="file_modification_destruction" name="C:\Documents and Settings\Administrator\Cookies\administrator@walkernews[1].txt"/>
				<file_deleted name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\config[1].bin"/>
				<file_deleted name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\gate[1].htm"/>
				<file_deleted name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\webhp[1].htm"/>
				<file_modified name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.awd"/>
				<file_modified name="C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt"/>
				<file_modified name="C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt"/>
				<file_modified name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\config[1].bin"/>
				<file_modified name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\gate[1].htm"/>
				<file_modified name="C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WDUF49AN\webhp[1].htm"/>
				<file_modified name="PIPE\lsarpc"/>
				<file_modified description="file_modification_destruction" name="\Device\Afd\Endpoint"/>
				<file_modified description="file_modification_destruction" name="\Device\RasAcd"/>
				<file_read name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.awd"/>
				<file_read name="C:\Documents and Settings\Administrator\Application Data\Microsoft\Address Book\Administrator.wab"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@java[1].txt"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@promotion.adobe[1].txt"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@sun[1].txt"/>
				<file_read name="C:\Documents and Settings\Administrator\Cookies\administrator@walkernews[1].txt"/>
				<file_read name="PIPE\lsarpc"/>
				<file_read name="c:\autoexec.bat"/>
				<file_renamed description="file_modification_destruction" new_name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.tmp" old_name="C:\Documents and Settings\Administrator\Application Data\Abbi\orxiy.awd"/>
				<section_object_created file_name="C:\Program Files\Common Files\System\directdb.dll" section_name=""/>
				<section_object_created file_name="C:\Program Files\Common Files\System\wab32.dll" section_name=""/>
				<section_object_created file_name="C:\Program Files\Common Files\System\wab32res.dll" section_name=""/>
				<section_object_created file_name="C:\Program Files\Outlook Express\msoe.dll" section_name=""/>
				<section_object_created file_name="C:\Program Files\Outlook Express\msoeres.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\System32\wshtcpip.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\DNSAPI.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\INETCOMM.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSOERT2.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\PSTOREC.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\RASAPI32.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\TAPI32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\acctres.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\hnetcfg.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\inetres.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\mlang.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\msident.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\msidntld.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\msoeacct.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\mswsock.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\rasadhlp.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\rasman.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\sensapi.dll" section_name=""/>
				<section_object_created file_name="C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Microsoft\Outlook Express\Folders.dbx" section_name="BaseNamedObjects\c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_folders.dbx_directdbfilemap"/>
				<section_object_created file_name="C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Microsoft\Outlook Express\Inbox.dbx" section_name="BaseNamedObjects\c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_inbox.dbx_directdbfilemap"/>
				<section_object_created file_name="C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Microsoft\Outlook Express\Offline.dbx" section_name="BaseNamedObjects\c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_offline.dbx_directdbfilemap"/>
				<section_object_created file_name="C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{42D8066E-F069-48E2-9549-21646EC1BC68}\Microsoft\Outlook Express\Sent Items.dbx" section_name="BaseNamedObjects\c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_sent items.dbx_directdbfilemap"/>
				<fs_control_communication control_code="0x0011C017" count="69" file="PIPE\lsarpc"/>
				<device_control_communication control_code="AFD_GET_INFO (0x0001207B)" count="2" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_SET_CONTEXT (0x00012047)" count="24" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_BIND (0x00012003)" count="4" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_GET_TDI_HANDLES (0x00012037)" count="8" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_START_LISTEN (0x0001200B)" count="1" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_GET_SOCK_NAME (0x0001202F)" count="5" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_SET_INFO (0x0001203B)" count="4" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_EVENT_SELECT (0x00012087)" count="1" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_CONNECT (0x00012007)" count="3" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="0x00120028" count="3" file="unnamed file"/>
				<device_control_communication control_code="AFD_SEND (0x0001201F)" count="3" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_RECV (0x00012017)" count="20" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="0x000120B3" count="1" file="\Device\Afd\Endpoint"/>
				<device_control_communication control_code="AFD_DISCONNECT (0x0001202B)" count="1" file="\Device\Afd\Endpoint"/>
				<directory_monitored count="1" directory="C:\Documents and Settings\Administrator\Application Data\Microsoft\Address Book" notify_filter="Last Write Change" watch_subtree="0"/>
			</file_activities>
			<process_activities>
			  <foreign_mem_area_write process="C:\WINDOWS\system32\wscntfy.exe"/>
			</process_activities>
			<network_activities>
			  <sockets>
				  <socket close_time="not-a-date-time" create_time="2011-Dec-31 04:50:49.020353" created_by_thread="4" foreign_ip="" foreign_port="0" is_listening="1" local_ip="0.0.0.0" local_port="30488" type="tcp"/>
					<socket close_time="2011-Dec-31 04:51:39.333815" create_time="2011-Dec-31 04:51:35.097364" created_by_thread="6" foreign_ip="46.166.148.131" foreign_port="80" is_listening="0" local_ip="0.0.0.0" local_port="1028" type="tcp"/>
					<socket close_time="2011-Dec-31 04:52:31.170740" create_time="2011-Dec-31 04:52:24.528478" created_by_thread="8" foreign_ip="209.85.147.147" foreign_port="80" is_listening="0" local_ip="0.0.0.0" local_port="1029" type="tcp"/>
					<socket close_time="2011-Dec-31 04:52:31.977023" create_time="2011-Dec-31 04:52:31.962043" created_by_thread="8" foreign_ip="" foreign_port="0" is_listening="0" local_ip="" local_port="0" type="udp"/>
					<socket close_time="2011-Dec-31 04:53:04.740034" create_time="2011-Dec-31 04:52:34.120407" created_by_thread="8" foreign_ip="46.166.148.131" foreign_port="80" is_listening="0" local_ip="0.0.0.0" local_port="1030" type="tcp"/>
				</sockets>
				<dns_queries>
				  <dns_query dest_ip="192.168.0.1" dest_port="53" name="www.google.com" protocol="udp" result="209.85.147.147 209.85.147.99 209.85.147.103 209.85.147.104 209.85.147.105 209.85.147.106" src_ip="192.168.0.2" src_port="1025" successful="YES" type="DNS_TYPE_A"/>
				</dns_queries>
				<tcp_traffic>
				  <http_traffic>
					  <http_conversation dest_ip="46.166.148.131" dest_port="80" hostname="46.166.148.131" src_ip="192.168.0.2" src_port="1028" start_time="2011-12-31 04:51:35.413281">
						  <http_request request="GET /~klejdic/k1/config.bin " response="200 &quot;OK&quot; "/>
						</http_conversation>
						<http_conversation dest_ip="209.85.147.147" dest_port="80" hostname="www.google.com" src_ip="192.168.0.2" src_port="1029" start_time="2011-12-31 04:52:24.565616">
						  <http_request request="GET /webhp " response="200 &quot;OK&quot; "/>
						</http_conversation>
						<http_conversation dest_ip="46.166.148.131" dest_port="80" hostname="46.166.148.131" src_ip="192.168.0.2" src_port="1030" start_time="2011-12-31 04:52:34.299738">
						  <http_request request="POST /~klejdic/k1/gate.php " response="200 &quot;OK&quot; "/>
						</http_conversation>
					</http_traffic>
				</tcp_traffic>
				
			</network_activities>
			<misc_activities>
			  <mutex_created name="Global\{0EA6C97A-819F-C1BA-0941-FA02A5E203D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-0D40-FA02A1E303D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-2543-FA0289E003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-3541-FA0299E203D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-3546-FA0299E503D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-3D42-FA0291E103D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-4143-FA02EDE003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-5D40-FA02F1E303D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-5D43-FA02F1E003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-7543-FA02D9E003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-9140-FA023DE303D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-9544-FA0239E703D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-A543-FA0209E003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-A941-FA0205E203D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-A943-FA0205E003D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-AD47-FA0201E403D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-DD44-FA0271E703D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-E144-FA024DE703D0}"/>
				<mutex_created name="Global\{0EA6C97A-819F-C1BA-E944-FA0245E703D0}"/>
				<mutex_created name="Global\{2BFF9DE0-D505-E4E3-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{41C77EC2-3627-8EDB-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{41C77EC3-3626-8EDB-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{4D2BA9F6-E113-8237-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{4D2BA9F9-E11C-8237-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{A987AD72-E597-669B-C8B9-195C641AE08E}"/>
				<mutex_created name="Global\{BE841225-5AC0-7198-C8B9-195C641AE08E}"/>
				<mutex_created name="Local\{2021C8D5-8030-EF3D-C8B9-195C641AE08E}"/>
				<mutex_created name="Local\{2021C8D6-8033-EF3D-C8B9-195C641AE08E}"/>
				<mutex_created name="MPSWABOlkStoreNotifyMutex"/>
				<mutex_created name="MPSWabDataAccessMutex"/>
				<mutex_created name="MSIdent Logon"/>
				<mutex_created name="OutlookExpress_InstanceMutex_101897"/>
				<mutex_created name="c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_folders.dbx_directdbmutex"/>
				<mutex_created name="c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_inbox.dbx_directdbmutex"/>
				<mutex_created name="c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_offline.dbx_directdbmutex"/>
				<mutex_created name="c:_documents and settings_administrator_local settings_application data_identities_{42d8066e-f069-48e2-9549-21646ec1bc68}_microsoft_outlook express_sent items.dbx_directdbmutex"/>
				<mutex_created name="microsoft_thor_folder_notifyinfo_mutex"/>
				<key_was_checked count="154" key="VK_LBUTTON (1)"/>
				<key_was_checked count="35" key="VK_ESCAPE (27)"/>
			</misc_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>5</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>ctfmon.exe</virtual_fn>
			<virtual_path>C:\WINDOWS\system32\ctfmon.exe</virtual_path>
			<arguments>"C:\WINDOWS\system32\ctfmon.exe" </arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>5f1d5f88303d4a4dbc8e5f97ba967cc3</md5>
			<sha1>99cb7370f16773c8e2d0c86fe805ec638ab126e9</sha1>
			<file_size>15360</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x5FC10000" base_name="MSUTB.dll" full_name="C:\WINDOWS\system32\MSUTB.dll" is_load_time_dependency="1" load_time="1" size="0x00033000"/>
			<loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
			<loaded_dll base_address="0x6F880000" base_name="AcGenral.DLL" full_name="C:\WINDOWS\AppPatch\AcGenral.DLL" is_load_time_dependency="1" load_time="1" size="0x001CA000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77BE0000" base_name="MSACM32.dll" full_name="C:\WINDOWS\system32\MSACM32.dll" is_load_time_dependency="1" load_time="1" size="0x00015000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
			<loaded_dll base_address="0x5AD70000" base_name="UxTheme.dll" full_name="C:\WINDOWS\system32\UxTheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="0" load_time="2" size="0x00017000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="0" load_time="2" size="0x000AA000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="0" load_time="2" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Run" notify_filter="Key Change,Value Change" watch_subtree="1"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="PIPE\lsarpc"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<fs_control_communication control_code="0x0011C017" count="4" file="PIPE\lsarpc"/>
			</file_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>6</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>msmsgs.exe</virtual_fn>
			<virtual_path>C:\Program Files\Messenger\msmsgs.exe</virtual_path>
			<arguments>"C:\Program Files\Messenger\msmsgs.exe" /background</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>3e930c641079443d4de036167a69caa2</md5>
			<sha1>ac40479e28fb680aff76e41fa14ebe18b3392629</sha1>
			<file_size>1695232</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x71AD0000" base_name="WSOCK32.dll" full_name="C:\WINDOWS\system32\WSOCK32.dll" is_load_time_dependency="1" load_time="1" size="0x00009000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x773D0000" base_name="COMCTL32.dll" full_name="C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x763B0000" base_name="comdlg32.dll" full_name="C:\WINDOWS\system32\comdlg32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x4EC50000" base_name="gdiplus.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\gdiplus.dll" is_load_time_dependency="1" load_time="1" size="0x001A6000"/>
			<loaded_dll base_address="0x76380000" base_name="MSIMG32.dll" full_name="C:\WINDOWS\system32\MSIMG32.dll" is_load_time_dependency="1" load_time="1" size="0x00005000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00055000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="1" load_time="1" size="0x000AA000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="1" load_time="1" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x76790000" base_name="cryptdll.dll" full_name="C:\WINDOWS\system32\cryptdll.dll" is_load_time_dependency="1" load_time="1" size="0x0000C000"/>
			<loaded_dll base_address="0x76D60000" base_name="iphlpapi.dll" full_name="C:\WINDOWS\system32\iphlpapi.dll" is_load_time_dependency="1" load_time="1" size="0x00019000"/>
			<loaded_dll base_address="0x10000000" base_name="XPOB2RES.DLL" full_name="C:\WINDOWS\system32\XPOB2RES.DLL" is_load_time_dependency="1" load_time="1" size="0x0006C000"/>
			<loaded_dll base_address="0x76FD0000" base_name="CLBCATQ.DLL" full_name="C:\WINDOWS\system32\CLBCATQ.DLL" is_load_time_dependency="1" load_time="1" size="0x0007F000"/>
			<loaded_dll base_address="0x77050000" base_name="COMRes.dll" full_name="C:\WINDOWS\system32\COMRes.dll" is_load_time_dependency="1" load_time="1" size="0x000C5000"/>
			<loaded_dll base_address="0x00890000" base_name="xpsp2res.dll" full_name="C:\WINDOWS\system32\xpsp2res.dll" is_load_time_dependency="1" load_time="1" size="0x002C5000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x7E720000" base_name="SXS.DLL" full_name="C:\WINDOWS\system32\SXS.DLL" is_load_time_dependency="1" load_time="1" size="0x000B0000"/>
			<loaded_dll base_address="0x77710000" base_name="es.dll" full_name="C:\WINDOWS\system32\es.dll" is_load_time_dependency="1" load_time="1" size="0x00042000"/>
			<loaded_dll base_address="0x76F50000" base_name="wtsapi32.dll" full_name="C:\WINDOWS\system32\wtsapi32.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76360000" base_name="WINSTA.dll" full_name="C:\WINDOWS\system32\WINSTA.dll" is_load_time_dependency="1" load_time="1" size="0x00010000"/>
			<loaded_dll base_address="0x76C00000" base_name="credui.dll" full_name="C:\WINDOWS\system32\credui.dll" is_load_time_dependency="1" load_time="1" size="0x0002E000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\CLSID\{00020420-0000-0000-C000-000000000046}\INPROCSERVER32" value_data="oleaut32.dll" value_name=""/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\CLSID\{00020420-0000-0000-C000-000000000046}\INPROCSERVER32" value_data="Both" value_name="ThreadingModel"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{00020400-0000-0000-C000-000000000046}\PROXYSTUBCLSID32" value_data="{00020420-0000-0000-C000-000000000046}" value_name=""/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{D597BAB1-5B9F-11D1-8DD2-00AA004ABD5E}\TYPELIB" value_data="{D597DEED-5B9F-11D1-8DD2-00AA004ABD5E}" value_name=""/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\INTERFACE\{D597BAB1-5B9F-11D1-8DD2-00AA004ABD5E}\TYPELIB" value_data="2.0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\SOFTWARE\CLASSES\TYPELIB\{00020430-0000-0000-C000-000000000046}\2.0\0\WIN32" value_data="C:\WINDOWS\system32\stdole2.tlb" value_name=""/>
				<reg_value_read count="2" key="HKLM\SOFTWARE\CLASSES\TYPELIB\{D597DEED-5B9F-11D1-8DD2-00AA004ABD5E}\2.0\0\WIN32" value_data="C:\WINDOWS\system32\SENS.DLL" value_name=""/>
				<reg_value_read count="4" key="HKLM\Software\Microsoft\COM3" value_data="0x0b00000000000000" value_name="REGDBVersion"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\MESSENGERSERVICE" value_data="0x01000000" value_name="MSNState"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKU" notify_filter="Key Change,Value Change" watch_subtree="1"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="PIPE\lsarpc"/>
				<file_read name="C:\WINDOWS\system32\SENS.DLL"/>
				<file_read name="C:\WINDOWS\system32\stdole2.tlb"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\system32\SENS.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\stdole2.tlb" section_name=""/>
				<fs_control_communication control_code="0x0011C017" count="5" file="PIPE\lsarpc"/>
			</file_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>7</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>reader_sl.exe</virtual_fn>
			<virtual_path>C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe</virtual_path>
			<arguments>"C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe" </arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>54c88bfbd055621e2306534f445c0c8d</md5>
			<sha1>960a171e826c077187fe634103874644327a6110</sha1>
			<file_size>40048</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x7C420000" base_name="MSVCP80.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCP80.dll" is_load_time_dependency="1" load_time="1" size="0x00087000"/>
			<loaded_dll base_address="0x78130000" base_name="MSVCR80.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x0009A000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="0" load_time="2" size="0x00017000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="0" load_time="2" size="0x0008B000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="0" load_time="2" size="0x000AA000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="0" load_time="2" size="0x0013D000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="0" load_time="2" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="PIPE\lsarpc"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<fs_control_communication control_code="0x0011C017" count="4" file="PIPE\lsarpc"/>
			</file_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>8</id>
			<parent_id>4</parent_id>
			<analysis_reason>Explorer.EXE wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>wscntfy.exe</virtual_fn>
			<virtual_path>C:\WINDOWS\system32\wscntfy.exe</virtual_path>
			<arguments>C:\WINDOWS\system32\wscntfy.exe</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>f92e1076c42fcd6db3d72d8cfe9816d5</md5>
			<sha1>549f0a01848375d03159fc74171ed97790fa9650</sha1>
			<file_size>13824</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x007C0000" base_name="xpsp2res.dll" full_name="C:\WINDOWS\system32\xpsp2res.dll" is_load_time_dependency="1" load_time="1" size="0x002C5000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x77B40000" base_name="Apphelp.dll" full_name="C:\WINDOWS\system32\Apphelp.dll" is_load_time_dependency="1" load_time="1" size="0x00022000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
		</dll_dependencies>
		<activities>
</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>9</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>kxuckd.exe</virtual_fn>
			<virtual_path>C:\Program Files\Common Files\kxuckd.exe</virtual_path>
			<arguments>"C:\Program Files\Common Files\kxuckd.exe"</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>ed22e108cca63fab4ad592f04b117289</md5>
			<sha1>a11b96e200594f19b8e67af04797b61267710fec</sha1>
			<file_size>327901</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x773D0000" base_name="COMCTL32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x763B0000" base_name="comdlg32.dll" full_name="C:\WINDOWS\system32\comdlg32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x71B20000" base_name="MPR.dll" full_name="C:\WINDOWS\system32\MPR.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x71AD0000" base_name="WSOCK32.dll" full_name="C:\WINDOWS\system32\WSOCK32.dll" is_load_time_dependency="1" load_time="1" size="0x00009000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x5AD70000" base_name="uxtheme.dll" full_name="C:\WINDOWS\system32\uxtheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
			<loaded_dll base_address="0x77920000" base_name="SETUPAPI.dll" full_name="C:\WINDOWS\system32\SETUPAPI.dll" is_load_time_dependency="1" load_time="1" size="0x000F3000"/>
			<loaded_dll base_address="0x74720000" base_name="MSCTF.dll" full_name="C:\WINDOWS\system32\MSCTF.dll" is_load_time_dependency="1" load_time="1" size="0x0004C000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="0" load_time="2" size="0x000AA000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="0" load_time="2" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="PIPE\lsarpc"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<fs_control_communication control_code="0x0011C017" count="4" file="PIPE\lsarpc"/>
			</file_activities>
		</activities>
		<sigbuster>UPX All_Versions SN:1634</sigbuster>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>10</id>
			<parent_id>3</parent_id>
			<analysis_reason>olne.exe wrote to the virtual memory of this process</analysis_reason>
			<virtual_fn>drlwszvxbeo.exe</virtual_fn>
			<virtual_path>C:\Program Files\Common Files\drlwszvxbeo.exe</virtual_path>
			<arguments>"C:\Program Files\Common Files\drlwszvxbeo.exe"</arguments>
			<status>alive</status>
			<exit_code>0</exit_code>
			<md5>ec95a4d3adc866c53bfafc3ba177d905</md5>
			<sha1>78d7358cebb7681ba22b1ec453eb98308eadd619</sha1>
			<file_size>1256684</file_size>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.DLL" full_name="C:\WINDOWS\system32\ADVAPI32.DLL" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x76BF0000" base_name="PSAPI.DLL" full_name="C:\WINDOWS\system32\PSAPI.DLL" is_load_time_dependency="1" load_time="1" size="0x0000B000"/>
			<loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
			<loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="0" load_time="2" size="0x0009A000"/>
			<loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
			<loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="0" load_time="2" size="0x00017000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="0" load_time="2" size="0x0008B000"/>
			<loaded_dll base_address="0x771B0000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="0" load_time="2" size="0x000AA000"/>
			<loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="0" load_time="2" size="0x00103000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="0" load_time="2" size="0x0013D000"/>
			<loaded_dll base_address="0x77A80000" base_name="CRYPT32.dll" full_name="C:\WINDOWS\system32\CRYPT32.dll" is_load_time_dependency="0" load_time="2" size="0x00095000"/>
			<loaded_dll base_address="0x77B20000" base_name="MSASN1.dll" full_name="C:\WINDOWS\system32\MSASN1.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="0" load_time="2" size="0x00049000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00076000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="0" load_time="2" size="0x00817000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="0" load_time="2" size="0x00091000"/>
		</dll_dependencies>
		<program_output>
		  <stdout>...</stdout>
		</program_output>
		<activities>
		  <registry_activities>
			  <reg_value_modified count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="PC" value_name="ComputerName"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
				<reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1020" value_name="Next_Catalog_Entry_ID"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="13" value_name="Num_Catalog_Entries"/>
				<reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="6" value_name="Serial_Access_Num"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Wyfa" value_data="0xdbe93b39f066d4b5cb4cb74f4498aba43bdee15a1165b16bd1993ce009c4" value_name="Iwygi"/>
				<reg_value_read count="2" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Privacy" value_data="0" value_name="CleanCookies"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" value_data="0" value_name="1609"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1406"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4" value_data="0" value_name="1609"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
				<reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
			</registry_activities>
			<file_activities>
			  <file_modified name="PIPE\lsarpc"/>
				<file_read name="PIPE\lsarpc"/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WININET.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2HELP.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WS2_32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
				<device_control_communication control_code="0x00390008" count="1" file="\Device\KsecDD"/>
				<fs_control_communication control_code="0x0011C017" count="4" file="PIPE\lsarpc"/>
			</file_activities>
		</activities>
	</analysis_subject>
	<analysis_subject>
	  <general>
		  <id>11</id>
			<parent_id>2</parent_id>
			<analysis_reason>Started by dec8ffd4ea.exe</analysis_reason>
			<virtual_fn>cmd.exe</virtual_fn>
			<virtual_path>cmd.exe</virtual_path>
			<status>alive</status>
			<exit_code>0</exit_code>
		</general>
		<dll_dependencies>
		  <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
			<loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
			<loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
			<loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
			<loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
			<loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
			<loaded_dll base_address="0x6F880000" base_name="AcGenral.DLL" full_name="C:\WINDOWS\AppPatch\AcGenral.DLL" is_load_time_dependency="1" load_time="1" size="0x001CA000"/>
			<loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
			<loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
			<loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
			<loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="1" load_time="1" size="0x0002D000"/>
			<loaded_dll base_address="0x774E0000" base_name="ole32.dll" full_name="C:\WINDOWS\system32\ole32.dll" is_load_time_dependency="1" load_time="1" size="0x0013D000"/>
			<loaded_dll base_address="0x77120000" base_name="OLEAUT32.dll" full_name="C:\WINDOWS\system32\OLEAUT32.dll" is_load_time_dependency="1" load_time="1" size="0x0008B000"/>
			<loaded_dll base_address="0x77BE0000" base_name="MSACM32.dll" full_name="C:\WINDOWS\system32\MSACM32.dll" is_load_time_dependency="1" load_time="1" size="0x00015000"/>
			<loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
			<loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="1" load_time="1" size="0x00817000"/>
			<loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
			<loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
			<loaded_dll base_address="0x5AD70000" base_name="UxTheme.dll" full_name="C:\WINDOWS\system32\UxTheme.dll" is_load_time_dependency="1" load_time="1" size="0x00038000"/>
		</dll_dependencies>
		<activities>
		  <registry_activities>
			  <reg_value_read count="1" key="HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" value_data="2592000" value_name="CriticalSectionTimeout"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
				<reg_value_read count="1" key="HKLM\SYSTEM\WPA\MediaCenter" value_data="0" value_name="Installed"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0x01000000100000000204000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0x01000000100000001100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0x0100000010000000550000001e000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0x01000000100000000200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0x01000000120000006001000016000000610100001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0x010000001000000006000000120000000700000012000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="3" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0x0100000010000000420000001c000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0x01000000100000003100000014000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0x01000000100000003001000016000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0x01000000100000002200000032000000" value_name="aFormatTagCache"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="0" value_name="cFilterTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="2" value_name="cFormatTags"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch" value_data="1" value_name="fdwSupport"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="midimapper"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.iac2"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="imaadp32.acm" value_name="msacm.imaadpcm"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.l3acm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="msadp32.acm" value_name="msacm.msadpcm"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msaudio1"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="msg711.acm" value_name="msacm.msg711"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msg723"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.msgsm610"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.sl_anet"/>
				<reg_value_read count="3" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="msacm.trspch"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.I420"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M261"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.M263"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.cvid"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv31"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv32"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv41"/>
				<reg_value_read count="1" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iv50"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.iyuv"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.mrle"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.msvc"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.uyvy"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yuy2"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvu9"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="vidc.yvyu"/>
				<reg_value_read count="2" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" value_data="" value_name="wavemapper"/>
				<reg_value_read count="1" key="HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers" value_data="1" value_name="TransparentEnabled"/>
				<reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm" value_data="1" value_name="wheel"/>
				<reg_value_read count="1" key="HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Multimedia\Audio" value_data="CD Quality,Radio Quality,Telephone Quality" value_name="SystemFormats"/>
			</registry_activities>
			<file_activities>
			  <section_object_created file_name="C:\WINDOWS\AppPatch\AcGenral.DLL" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\WindowsShell.Manifest" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\MSACM32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\ShimEng.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\UxTheme.dll" section_name=""/>
				<section_object_created file_name="C:\WINDOWS\system32\WINMM.dll" section_name=""/>
				<section_object_created file_name="C:\Windows\AppPatch\sysmain.sdb" section_name=""/>
				<fs_control_communication control_code="0x00090028" count="1" file="C:\Program Files\Common Files\"/>
				<device_control_communication control_code="0x00390008" count="1" file="\Device\KsecDD"/>
			</file_activities>
		</activities>
	</analysis_subject>
	<global_file_info>
	  <global_file info="MS-DOS executable" md5="8ed8abfaee8bd928a03d56b563f76f59" mimetype="application/x-dosexec" name="olne.exe" sha1="249133273ae1a3d3cfb725c571975ee829cbb5b7"/>
		<global_file info="data" md5="790dc9f11220c4035e67b49161265b1d" mimetype="application/octet-stream" name="gate[1].htm" sha1="78c9cb56be6121bc4867dfe5e6e34d557e94e6e2"/>
		<global_file info="HTML document text" md5="d7821eab634ec4c350f00ca5cb61ba7a" mimetype="text/html" name="webhp[1].htm" sha1="2fccb4444108ec589d7854c0615c52b5bb1b1269"/>
		<global_file info="data" md5="a2fb68423aace50643ff8403f83188f8" mimetype="application/octet-stream" name="orxiy.awd" sha1="909c7dd95bea5e4d40dec90748de9bb218ea79ab"/>
		<global_file info="MS-DOS batch file text" md5="335f737b48691546ee6d84dbb0a365ec" mimetype="text/x-msdos-batch" name="tmp82436790.bat" sha1="472c555a737d46d726a25c9e5408444ee05936c4"/>
		<global_file info="data" md5="66268fa6ad69d6a49cb556f79cca3370" mimetype="application/octet-stream" name="config[1].bin" sha1="c163f9189d09ff98d0b5fc546deb2c26c1b1d01f"/>
	</global_file_info>
</analysis>
