<?xml version="1.0" encoding="ISO-8859-1"?>
<analysis>
 <report_version>
  <major>3</major>
  <minor>1</minor>
 </report_version>
 <configuration>
  <time_needed>243 s</time_needed>
  <report_created>05/28/09, 09:19:12 UTC</report_created>
  <termination_reason>Timeout</termination_reason>
  <ttanalyze_version>
   <prog_version>1.68.0</prog_version>
   <svn_revision>$Revision: 1908 $</svn_revision>
   <build_date>May 16 2009 12:59:27</build_date>
  </ttanalyze_version>
 </configuration>
 <summary>
  <auto_start>true</auto_start>
  <internet_settings>true</internet_settings>
  <bho>false</bho>
  <win_dir_copy>true</win_dir_copy>
  <av_kill>false</av_kill>
  <com_object>false</com_object>
  <dlf>false</dlf>
  <ircbot>false</ircbot>
  <spambot>true</spambot>
  <addressscan>false</addressscan>
  <portscan>false</portscan>
  <file_modification_destruction>true</file_modification_destruction>
  <process_spawn>false</process_spawn>
  <all_reg_activities>true</all_reg_activities>
  <severity_level>9</severity_level>
 </summary>
 <analysis_subject>
  <general>
   <id>2</id>
   <parent_id>1</parent_id>
   <analysis_reason>Primary Analysis Subject</analysis_reason>
   <submission_fn>82532</submission_fn>
   <virtual_fn>sample.exe</virtual_fn>
   <virtual_path>C:\sample.exe</virtual_path>
   <arguments>"C:\sample.exe"</arguments>
   <status>alive</status>
   <exit_code>0</exit_code>
   <md5>3d23ec8b55840b95ea75197ce9446b6d</md5>
   <sha1>272ce73adebba81983abbbf112155e463951d046</sha1>
   <file_size>24840</file_size>
  </general>
  <dll_dependencies>
   <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
   <loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
   <loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
   <loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
   <loaded_dll base_address="0x42C10000" base_name="WININET.dll" full_name="C:\WINDOWS\system32\WININET.dll" is_load_time_dependency="1" load_time="1" size="0x000CF000"/>
   <loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
   <loaded_dll base_address="0x77F60000" base_name="SHLWAPI.dll" full_name="C:\WINDOWS\system32\SHLWAPI.dll" is_load_time_dependency="1" load_time="1" size="0x00076000"/>
   <loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
   <loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
   <loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
   <loaded_dll base_address="0x00330000" base_name="Normaliz.dll" full_name="C:\WINDOWS\system32\Normaliz.dll" is_load_time_dependency="1" load_time="1" size="0x00009000"/>
   <loaded_dll base_address="0x42990000" base_name="iertutil.dll" full_name="C:\WINDOWS\system32\iertutil.dll" is_load_time_dependency="1" load_time="1" size="0x00045000"/>
   <loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
   <loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
   <loaded_dll base_address="0x76D60000" base_name="iphlpapi.dll" full_name="C:\WINDOWS\system32\iphlpapi.dll" is_load_time_dependency="1" load_time="1" size="0x00019000"/>
   <loaded_dll base_address="0x76390000" base_name="IMM32.DLL" full_name="C:\WINDOWS\system32\IMM32.DLL" is_load_time_dependency="1" load_time="1" size="0x0001D000"/>
   <loaded_dll base_address="0x773D0000" base_name="comctl32.dll" full_name="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll" is_load_time_dependency="1" load_time="1" size="0x00103000"/>
   <loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x00055000"/>
   <loaded_dll base_address="0x5D090000" base_name="comctl32.dll" full_name="C:\WINDOWS\system32\comctl32.dll" is_load_time_dependency="0" load_time="2" size="0x0009A000"/>
   <loaded_dll base_address="0x662B0000" base_name="hnetcfg.dll" full_name="C:\WINDOWS\system32\hnetcfg.dll" is_load_time_dependency="0" load_time="2" size="0x00058000"/>
   <loaded_dll base_address="0x71A50000" base_name="mswsock.dll" full_name="C:\WINDOWS\system32\mswsock.dll" is_load_time_dependency="0" load_time="2" size="0x0003F000"/>
   <loaded_dll base_address="0x71A90000" base_name="wshtcpip.dll" full_name="C:\WINDOWS\System32\wshtcpip.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
   <loaded_dll base_address="0x722B0000" base_name="sensapi.dll" full_name="C:\WINDOWS\system32\sensapi.dll" is_load_time_dependency="0" load_time="2" size="0x00005000"/>
   <loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="0" load_time="2" size="0x000B4000"/>
   <loaded_dll base_address="0x76B40000" base_name="WINMM.dll" full_name="C:\WINDOWS\system32\WINMM.dll" is_load_time_dependency="0" load_time="2" size="0x0002D000"/>
   <loaded_dll base_address="0x76E80000" base_name="rtutils.dll" full_name="C:\WINDOWS\system32\rtutils.dll" is_load_time_dependency="0" load_time="2" size="0x0000E000"/>
   <loaded_dll base_address="0x76E90000" base_name="rasman.dll" full_name="C:\WINDOWS\system32\rasman.dll" is_load_time_dependency="0" load_time="2" size="0x00012000"/>
   <loaded_dll base_address="0x76EB0000" base_name="TAPI32.dll" full_name="C:\WINDOWS\system32\TAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x0002F000"/>
   <loaded_dll base_address="0x76EE0000" base_name="RASAPI32.dll" full_name="C:\WINDOWS\system32\RASAPI32.dll" is_load_time_dependency="0" load_time="2" size="0x0003C000"/>
   <loaded_dll base_address="0x76F20000" base_name="DNSAPI.dll" full_name="C:\WINDOWS\system32\DNSAPI.dll" is_load_time_dependency="0" load_time="2" size="0x00027000"/>
   <loaded_dll base_address="0x76F60000" base_name="WLDAP32.dll" full_name="C:\WINDOWS\system32\WLDAP32.dll" is_load_time_dependency="0" load_time="2" size="0x0002C000"/>
   <loaded_dll base_address="0x76FB0000" base_name="winrnr.dll" full_name="C:\WINDOWS\System32\winrnr.dll" is_load_time_dependency="0" load_time="2" size="0x00008000"/>
   <loaded_dll base_address="0x76FC0000" base_name="rasadhlp.dll" full_name="C:\WINDOWS\system32\rasadhlp.dll" is_load_time_dependency="0" load_time="2" size="0x00006000"/>
   <loaded_dll base_address="0x7C9C0000" base_name="SHELL32.dll" full_name="C:\WINDOWS\system32\SHELL32.dll" is_load_time_dependency="0" load_time="2" size="0x00817000"/>
  </dll_dependencies>
  <activities>
   <registry_activities>
    <reg_value_modified count="1" description="auto_start" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" value_data="C:\WINDOWS\winlogon.exe -stealth" value_name="ICQ Net"/>
    <reg_value_modified count="1" description="internet_settings" key="HKLM\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
    <reg_value_modified count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\All Users\Application Data" value_name="Common AppData"/>
    <reg_value_modified count="3" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Application Data" value_name="AppData"/>
    <reg_value_modified count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Local Settings\Temporary Internet Files" value_name="Cache"/>
    <reg_value_modified count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Cookies" value_name="Cookies"/>
    <reg_value_modified count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" value_data="C:\Documents and Settings\user\Local Settings\History" value_name="History"/>
    <reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
    <reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
    <reg_value_modified count="1" description="internet_settings" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x460000006800000001000000000000000000000000000000040000000000" value_name="SavedLegacySettings"/>
    <reg_value_read count="2" key="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0x00000000" value_name="UrlEncoding"/>
    <reg_value_read count="8" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\NETBT\PARAMETERS" value_data="4" value_name="DhcpNodeType"/>
    <reg_value_read count="16" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\LINKAGE" value_data="0x5c004400650076006900630065005c007b00420032004200350031003000" value_name="Bind"/>
    <reg_value_read count="8" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS" value_data="" value_name="Domain"/>
    <reg_value_read count="16" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS" value_data="user" value_name="Hostname"/>
    <reg_value_read count="8" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS" value_data="0" value_name="IPEnableRouter"/>
    <reg_value_read count="16" key="HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874}" value_data="255.255.255.255" value_name="DhcpServer"/>
    <reg_value_read count="8" key="HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874}" value_data="0" value_name="EnableDHCP"/>
    <reg_value_read count="32" key="HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2B51064-BBF5-4528-B62B-E6D62A782874}" value_data="192.168.0.1" value_name="NameServer"/>
    <reg_value_read count="2" key="HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters" value_data="0x5400630070006900700000004e0065007400420049004f00530000000000" value_name="Transports"/>
    <reg_value_read count="1" key="HKLM\SYSTEM\Setup" value_data="0" value_name="SystemSetupInProgress"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Tracing" value_data="0" value_name="EnableConsoleTracing"/>
    <reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="ConsoleTracingMask"/>
    <reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableConsoleTracing"/>
    <reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="0" value_name="EnableFileTracing"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="%windir%\tracing" value_name="FileDirectory"/>
    <reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="4294901760" value_name="FileTracingMask"/>
    <reg_value_read count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" value_data="1048576" value_name="MaxFileSize"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="All Users" value_name="AllUsersProfile"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="Default User" value_name="DefaultUserProfile"/>
    <reg_value_read count="8" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList" value_data="%SystemDrive%\Documents and Settings" value_name="ProfilesDirectory"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1229272821-1004336348-527237240-1003" value_data="%SystemDrive%\Documents and Settings\user" value_name="ProfileImagePath"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files\Common Files" value_name="CommonFilesDir"/>
    <reg_value_read count="4" key="HKLM\Software\Microsoft\Windows\CurrentVersion" value_data="C:\Program Files" value_name="ProgramFilesDir"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%ALLUSERSPROFILE%\Application Data" value_name="Common AppData"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="1" value_name="PerUserItem"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="1" value_name="PerUserItem"/>
    <reg_value_read count="1" key="HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="1" value_name="PerUserItem"/>
    <reg_value_read count="5" key="HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName" value_data="USER" value_name="ComputerName"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm" value_data="1" value_name="wheel"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Control\ProductOptions" value_data="WinNT" value_name="ProductType"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32\cmd.exe" value_name="ComSpec"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="NO" value_name="FP_NO_HOST_CHECK"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="1" value_name="NUMBER_OF_PROCESSORS"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="Windows_NT" value_name="OS"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH" value_name="PATHEXT"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86" value_name="PROCESSOR_ARCHITECTURE"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="x86 Family 6 Model 3 Stepping 3, GenuineIntel" value_name="PROCESSOR_IDENTIFIER"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="6" value_name="PROCESSOR_LEVEL"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="0303" value_name="PROCESSOR_REVISION"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem" value_name="Path"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TEMP"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%\TEMP" value_name="TMP"/>
    <reg_value_read count="8" key="HKLM\System\CurrentControlSet\Control\Session Manager\Environment" value_data="%SystemRoot%" value_name="windir"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\LDAP" value_data="1" value_name="LdapClientIntegrity"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="" value_name="Domain"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="user" value_name="Hostname"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters" value_data="1" value_name="UseDomainNameDevolution"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="%SystemRoot%\System32\wshtcpip.dll" value_name="HelperDllName"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="0x0b0000000300000002000000010000000600000002000000010000000000" value_name="Mapping"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="16" value_name="MaxSockaddrLength"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="16" value_name="MinSockaddrLength"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock" value_data="0" value_name="UseDelayedAcceptance"/>
    <reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters" value_data="2.0" value_name="WinSock_Registry_Version"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="3" value_name="Num_Catalog_Entries"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" value_data="4" value_name="Serial_Access_Num"/>
    <reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="Tcpip" value_name="DisplayString"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="1" value_name="Enabled"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0x409d05229e7ecf11ae5a00aa00a7112b" value_name="ProviderId"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="StoresServiceClassInfo"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="12" value_name="SupportedNameSpace"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001" value_data="0" value_name="Version"/>
    <reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="NTDS" value_name="DisplayString"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="1" value_name="Enabled"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="%SystemRoot%\System32\winrnr.dll" value_name="LibraryPath"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0xee37263b80e5cf11a55500c04fd8d4ac" value_name="ProviderId"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="StoresServiceClassInfo"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="32" value_name="SupportedNameSpace"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002" value_data="0" value_name="Version"/>
    <reg_value_read count="4" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="Network Location Awareness (NLA) Namespace" value_name="DisplayString"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="1" value_name="Enabled"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="%SystemRoot%\System32\mswsock.dll" value_name="LibraryPath"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0x3a244266a83ba64abaa52e0bd71fdd83" value_name="ProviderId"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="StoresServiceClassInfo"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="15" value_name="SupportedNameSpace"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003" value_data="0" value_name="Version"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="1012" value_name="Next_Catalog_Entry_ID"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="11" value_name="Num_Catalog_Entries"/>
    <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" value_data="4" value_name="Serial_Access_Num"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" value_data="%SystemRoot%\system32\rsvpsp.d" value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011" value_data="%SystemRoot%\system32\mswsock." value_name="PackedCatalogItem"/>
    <reg_value_read count="2" key="HKLM\System\Setup" value_data="0" value_name="SystemSetupInProgress"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TEMP"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Environment" value_data="%USERPROFILE%\Local Settings\Temp" value_name="TMP"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="1" value_name="EnableHttp1_1"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="1" value_name="EnableNegotiate"/>
    <reg_value_read count="4" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="multipart/mixed multipart/x-mixed-replace multipart/x-byteranges " value_name="MimeExclusionListForCache"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="160" value_name="SecureProtocols"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="0x01000000" value_name="WarnOnPost"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS" value_data="0" value_name="WarnOnZoneCrossing"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0" value_name="CertificateRevocation"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" value_data="0" value_name="DisableCachingOfSSLPages"/>
    <reg_value_read count="4" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" value_data="1" value_name="ParseAutoexec"/>
    <reg_value_read count="3" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Application Data" value_name="AppData"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings\Temporary Internet Files" value_name="Cache"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Cookies" value_name="Cookies"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings\History" value_name="History"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\Local Settings" value_name="Local Settings"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" value_data="%USERPROFILE%\My Documents" value_name="Personal"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache" value_data="Client UrlCache MMF Ver 5.2" value_name="Signature"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="163410" value_name="CacheLimit"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content" value_data="" value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="8192" value_name="CacheLimit"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies" value_data="Cookie:" value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008051620080517" value_data="8192" value_name="CacheLimit"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008051620080517" value_data="11" value_name="CacheOptions"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008051620080517" value_data="%USERPROFILE%\Local Settings\History\History.IE5\MSHist012008051620080517" value_name="CachePath"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008051620080517" value_data=":2008051620080517: " value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012008051620080517" value_data="0" value_name="CacheRepair"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData" value_data="1000" value_name="CacheLimit"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData" value_data="8" value_name="CacheOptions"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData" value_data="%USERPROFILE%\UserData" value_name="CachePath"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData" value_data="UserData" value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData" value_data="0" value_name="CacheRepair"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat" value_data="8192" value_name="CacheLimit"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat" value_data="0" value_name="CacheOptions"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat" value_data="%USERPROFILE%\Local Settings\Application Data\Microsoft\Feeds Cache" value_name="CachePath"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat" value_data="feedplat:" value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat" value_data="0" value_name="CacheRepair"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="8192" value_name="CacheLimit"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History" value_data="Visited:" value_name="CachePrefix"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="1" value_name="MigrateProxy"/>
    <reg_value_read count="1" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings" value_data="0" value_name="ProxyEnable"/>
    <reg_value_read count="2" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x3c0000000200000001000000000000000000000000000000040000000000" value_name="DefaultConnectionSettings"/>
    <reg_value_read count="4" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections" value_data="0x460000006700000001000000000000000000000000000000040000000000" value_name="SavedLegacySettings"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="C:\Documents and Settings\user\Application Data" value_name="APPDATA"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="" value_name="CLIENTNAME"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="C:" value_name="HOMEDRIVE"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="\Documents and Settings\user" value_name="HOMEPATH"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="" value_name="HOMESHARE"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="\\USER" value_name="LOGONSERVER"/>
    <reg_value_read count="8" key="HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment" value_data="Console" value_name="SESSIONNAME"/>
    <reg_key_monitored count="2" key="HKLM\Software\Microsoft\Tracing\RASAPI32" notify_filter="Attributes Change,Value Change,Security Descriptor Change" watch_subtree="0"/>
    <reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5" notify_filter="Key Change" watch_subtree="0"/>
    <reg_key_monitored count="1" key="HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9" notify_filter="Key Change" watch_subtree="0"/>
   </registry_activities>
   <file_activities>
    <file_created name="C:\WINDOWS\ranking_birth.zip"/>
    <file_created name="C:\WINDOWS\winlogon.exe"/>
    <file_modified description="file_modification_destruction" name="C:\WINDOWS\ranking_birth.zip"/>
    <file_modified description="file_modification_destruction" name="C:\WINDOWS\winlogon.exe"/>
    <file_modified description="file_modification_destruction" name="PIPE\lsarpc"/>
    <file_modified description="file_modification_destruction" name="\Device\Afd\Endpoint"/>
    <file_modified description="file_modification_destruction" name="\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}"/>
    <file_modified description="file_modification_destruction" name="\Device\RasAcd"/>
    <file_modified description="file_modification_destruction" name="\Device\Tcp"/>
    <file_read name="C:\WINDOWS\ranking_birth.zip"/>
    <file_read name="C:\sample.exe"/>
    <file_read name="PIPE\lsarpc"/>
    <file_read name="c:\autoexec.bat"/>
    <file_read name="c:\documents and settings\administrator\application data\microsoft\internet explorer\brndlog.txt"/>
    <file_read name="c:\documents and settings\administrator\local settings\application data\iconcache.db"/>
    <section_object_created file_name="C:\WINDOWS\System32\winrnr.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\System32\wshtcpip.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\DNSAPI.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\RASAPI32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\SHELL32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\TAPI32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\WINMM.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\comctl32.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\hnetcfg.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\mswsock.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\rasadhlp.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\rasman.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\rtutils.dll" section_name=""/>
    <section_object_created file_name="C:\WINDOWS\system32\sensapi.dll" section_name=""/>
    <section_object_created file_name="C:\sample.exe" section_name=""/>
    <device_control_communication control_code="0x00390008" count="8" file="\Device\KsecDD"/>
    <fs_control_communication control_code="0x0011C017" count="28" file="PIPE\lsarpc"/>
    <device_control_communication control_code="0x00120003" count="32" file="unnamed file"/>
    <device_control_communication control_code="0x00120040" count="16" file="unnamed file"/>
    <device_control_communication control_code="0x00120003" count="72" file="\Device\Tcp"/>
    <device_control_communication control_code="0x00120090" count="8" file="unnamed file"/>
    <device_control_communication control_code="0x0021009A" count="8" file="\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}"/>
    <device_control_communication control_code="AFD_GET_INFO (0x0001207B)" count="2" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_SET_CONTEXT (0x00012047)" count="36" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_BIND (0x00012003)" count="8" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_GET_TDI_HANDLES (0x00012037)" count="16" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_GET_SOCK_NAME (0x0001202F)" count="4" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_SEND_DATAGRAM (0x00012023)" count="4" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_RECV_DATAGRAM (0x0001201B)" count="4" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="0x00F14014" count="4" file="\Device\RasAcd"/>
    <device_control_communication control_code="AFD_CONNECT (0x00012007)" count="4" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_RECV (0x00012017)" count="1092" file="\Device\Afd\Endpoint"/>
    <device_control_communication control_code="AFD_SEND (0x0001201F)" count="62242" file="\Device\Afd\Endpoint"/>
   </file_activities>
   <service_activities>
    <service_started name="RASMAN"/>
   </service_activities>
   <process_activities>
    <thread_information>
     <thread_status number_of_threads="1" time="19"/>
    </thread_information>
   </process_activities>
   <network_activities>
    <sockets>
     <socket close_time="not-a-date-time" create_time="2009-May-28 09:16:12.511453" created_by_thread="5" foreign_ip="68.142.202.247" foreign_port="25" is_listening="0" local_ip="0.0.0.0" local_port="1040" type="tcp"/>
     <socket close_time="not-a-date-time" create_time="2009-May-28 09:16:10.024664" created_by_thread="4" foreign_ip="67.195.168.31" foreign_port="25" is_listening="0" local_ip="0.0.0.0" local_port="1037" type="tcp"/>
     <socket close_time="not-a-date-time" create_time="2009-May-28 09:16:10.071646" created_by_thread="7" foreign_ip="206.190.53.191" foreign_port="25" is_listening="0" local_ip="0.0.0.0" local_port="1038" type="tcp"/>
     <socket close_time="not-a-date-time" create_time="2009-May-28 09:16:10.705572" created_by_thread="6" foreign_ip="216.39.53.1" foreign_port="25" is_listening="0" local_ip="0.0.0.0" local_port="1039" type="tcp"/>
     <socket close_time="2009-May-28 09:16:05.141075" create_time="2009-May-28 09:16:04.208206" created_by_thread="4" foreign_ip="" foreign_port="0" is_listening="0" local_ip="0.0.0.0" local_port="1033" type="udp"/>
     <socket close_time="2009-May-28 09:16:06.108388" create_time="2009-May-28 09:16:04.228518" created_by_thread="7" foreign_ip="" foreign_port="0" is_listening="0" local_ip="0.0.0.0" local_port="1032" type="udp"/>
     <socket close_time="2009-May-28 09:16:06.610349" create_time="2009-May-28 09:16:05.991827" created_by_thread="5" foreign_ip="" foreign_port="0" is_listening="0" local_ip="0.0.0.0" local_port="1034" type="udp"/>
     <socket close_time="2009-May-28 09:16:09.025399" create_time="2009-May-28 09:16:07.154998" created_by_thread="6" foreign_ip="" foreign_port="0" is_listening="0" local_ip="0.0.0.0" local_port="1035" type="udp"/>
    </sockets>
    <dns_queries>
     <dns_query name="e.mx.mail.yahoo.com" result="216.39.53.1" successful="1" type="DNS_TYPE_A"/>
     <dns_query name="g.mx.mail.yahoo.com" result="206.190.53.191" successful="1" type="DNS_TYPE_A"/>
     <dns_query name="a.mx.mail.yahoo.com" result="67.195.168.31" successful="1" type="DNS_TYPE_A"/>
     <dns_query name="f.mx.mail.yahoo.com" result="68.142.202.247" successful="1" type="DNS_TYPE_A"/>
    </dns_queries>
    <tcp_traffic>
     <smtp_traffic>
      <smtp_conversation content="what do you think about it?" description="spambot" dest_ip="206.190.53.191" dest_port="25" recipient="skoorpio@yahoo.com" sender="skoorpio@yahoo.com" server_reply="none" src_ip="192.168.0.2" src_port="1038" subject="this is nothing for kids!">
       <attached_files content_type="application/octet-stream" file="old_photos.scr"/>
      </smtp_conversation>
      <smtp_conversation content="new patch is available!" description="spambot" dest_ip="67.195.168.31" dest_port="25" recipient="skoorpio@yahoo.com" sender="skoorpio@yahoo.com" server_reply="none" src_ip="192.168.0.2" src_port="1037" subject="fake?">
       <attached_files content_type="application/octet-stream" file="myaunt_unfolds.com"/>
      </smtp_conversation>
      <smtp_conversation content="your job? (I found that!)" description="spambot" dest_ip="68.142.202.247" dest_port="25" recipient="skoorpio@yahoo.com" sender="skoorpio@yahoo.com" server_reply="none" src_ip="192.168.0.2" src_port="1040" subject="Expired account ">
       <attached_files content_type="application/x-zip-compressed" file="ranking_birth.zip"/>
      </smtp_conversation>
      <smtp_conversation content="&lt;Server Error&gt;" description="spambot" dest_ip="216.39.53.1" dest_port="25" recipient="skoorpio@yahoo.com" sender="skoorpio@yahoo.com" server_reply="none" src_ip="192.168.0.2" src_port="1039" subject="warning">
       <attached_files content_type="application/octet-stream" file="warez.pif"/>
      </smtp_conversation>
     </smtp_traffic>
    </tcp_traffic>
    <udp_traffic>
     <unknown_udp_traffic>
      <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="28" res_bytes_sent="511" src_ip="192.168.0.2" src_port="1033" state="Normal establishment and termination"/>
      <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="28" res_bytes_sent="511" src_ip="192.168.0.2" src_port="1032" state="Normal establishment and termination"/>
      <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="28" res_bytes_sent="511" src_ip="192.168.0.2" src_port="1034" state="Normal establishment and termination"/>
      <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="28" res_bytes_sent="511" src_ip="192.168.0.2" src_port="1035" state="Normal establishment and termination"/>
     </unknown_udp_traffic>
    </udp_traffic>
   </network_activities>
   <misc_activities>
    <mutex_created name="[SkyNet.cz]SystemsMutex"/>
    <exception_occurred count="1" description="Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x41a135"/>
    <exception_occurred count="1" description="Exception 0x80000004 (STATUS_SINGLE_STEP) at 0x40710c"/>
   </misc_activities>
  </activities>
  <sigbuster>PEtite v2.x SN:1017
PEtite v2.2 SN:1575</sigbuster>
   <ikarus_scanner>
    <sig id="10082532" name="Email-Worm.Win32.NetSky"/>
   </ikarus_scanner>
  </analysis_subject>
  <analysis_subject>
   <general>
    <id>3</id>
    <parent_id>2</parent_id>
    <analysis_reason>NtConnectPort(\RPC Control\ntsvcs was called.</analysis_reason>
    <virtual_fn>services.exe</virtual_fn>
    <virtual_path>C:\WINDOWS\system32\services.exe</virtual_path>
    <arguments>C:\WINDOWS\system32\services.exe</arguments>
    <status>alive</status>
    <exit_code>0</exit_code>
    <md5>0e776ed5f7cc9f94299e70461b7b8185</md5>
    <sha1>cb5a33cec4c7b8ef4bd5dc8c241005b66b26cbbf</sha1>
    <file_size>108544</file_size>
   </general>
   <dll_dependencies>
    <loaded_dll base_address="0x7C900000" base_name="ntdll.dll" full_name="C:\WINDOWS\system32\ntdll.dll" is_load_time_dependency="1" load_time="1" size="0x000AF000"/>
    <loaded_dll base_address="0x7C800000" base_name="kernel32.dll" full_name="C:\WINDOWS\system32\kernel32.dll" is_load_time_dependency="1" load_time="1" size="0x000F6000"/>
    <loaded_dll base_address="0x77DD0000" base_name="ADVAPI32.dll" full_name="C:\WINDOWS\system32\ADVAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x0009B000"/>
    <loaded_dll base_address="0x77E70000" base_name="RPCRT4.dll" full_name="C:\WINDOWS\system32\RPCRT4.dll" is_load_time_dependency="1" load_time="1" size="0x00092000"/>
    <loaded_dll base_address="0x77FE0000" base_name="Secur32.dll" full_name="C:\WINDOWS\system32\Secur32.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
    <loaded_dll base_address="0x77C10000" base_name="msvcrt.dll" full_name="C:\WINDOWS\system32\msvcrt.dll" is_load_time_dependency="1" load_time="1" size="0x00058000"/>
    <loaded_dll base_address="0x5F770000" base_name="NCObjAPI.DLL" full_name="C:\WINDOWS\system32\NCObjAPI.DLL" is_load_time_dependency="1" load_time="1" size="0x0000C000"/>
    <loaded_dll base_address="0x76080000" base_name="MSVCP60.dll" full_name="C:\WINDOWS\system32\MSVCP60.dll" is_load_time_dependency="1" load_time="1" size="0x00065000"/>
    <loaded_dll base_address="0x7DBD0000" base_name="SCESRV.dll" full_name="C:\WINDOWS\system32\SCESRV.dll" is_load_time_dependency="1" load_time="1" size="0x00051000"/>
    <loaded_dll base_address="0x776C0000" base_name="AUTHZ.dll" full_name="C:\WINDOWS\system32\AUTHZ.dll" is_load_time_dependency="1" load_time="1" size="0x00012000"/>
    <loaded_dll base_address="0x7E410000" base_name="USER32.dll" full_name="C:\WINDOWS\system32\USER32.dll" is_load_time_dependency="1" load_time="1" size="0x00091000"/>
    <loaded_dll base_address="0x77F10000" base_name="GDI32.dll" full_name="C:\WINDOWS\system32\GDI32.dll" is_load_time_dependency="1" load_time="1" size="0x00049000"/>
    <loaded_dll base_address="0x769C0000" base_name="USERENV.dll" full_name="C:\WINDOWS\system32\USERENV.dll" is_load_time_dependency="1" load_time="1" size="0x000B4000"/>
    <loaded_dll base_address="0x7DBA0000" base_name="umpnpmgr.dll" full_name="C:\WINDOWS\system32\umpnpmgr.dll" is_load_time_dependency="1" load_time="1" size="0x00021000"/>
    <loaded_dll base_address="0x76360000" base_name="WINSTA.dll" full_name="C:\WINDOWS\system32\WINSTA.dll" is_load_time_dependency="1" load_time="1" size="0x00010000"/>
    <loaded_dll base_address="0x5B860000" base_name="NETAPI32.dll" full_name="C:\WINDOWS\system32\NETAPI32.dll" is_load_time_dependency="1" load_time="1" size="0x00055000"/>
    <loaded_dll base_address="0x5CB70000" base_name="ShimEng.dll" full_name="C:\WINDOWS\system32\ShimEng.dll" is_load_time_dependency="1" load_time="1" size="0x00026000"/>
    <loaded_dll base_address="0x47260000" base_name="AcAdProc.dll" full_name="C:\WINDOWS\AppPatch\AcAdProc.dll" is_load_time_dependency="1" load_time="1" size="0x0000F000"/>
    <loaded_dll base_address="0x76390000" base_name="IMM32.DLL" full_name="C:\WINDOWS\system32\IMM32.DLL" is_load_time_dependency="1" load_time="1" size="0x0001D000"/>
    <loaded_dll base_address="0x77B40000" base_name="Apphelp.dll" full_name="C:\WINDOWS\system32\Apphelp.dll" is_load_time_dependency="1" load_time="1" size="0x00022000"/>
    <loaded_dll base_address="0x77C00000" base_name="VERSION.dll" full_name="C:\WINDOWS\system32\VERSION.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
    <loaded_dll base_address="0x77B70000" base_name="eventlog.dll" full_name="C:\WINDOWS\system32\eventlog.dll" is_load_time_dependency="1" load_time="1" size="0x00011000"/>
    <loaded_dll base_address="0x76BF0000" base_name="PSAPI.DLL" full_name="C:\WINDOWS\system32\PSAPI.DLL" is_load_time_dependency="1" load_time="1" size="0x0000B000"/>
    <loaded_dll base_address="0x71AB0000" base_name="WS2_32.dll" full_name="C:\WINDOWS\system32\WS2_32.dll" is_load_time_dependency="1" load_time="1" size="0x00017000"/>
    <loaded_dll base_address="0x71AA0000" base_name="WS2HELP.dll" full_name="C:\WINDOWS\system32\WS2HELP.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
    <loaded_dll base_address="0x76F50000" base_name="wtsapi32.dll" full_name="C:\WINDOWS\system32\wtsapi32.dll" is_load_time_dependency="1" load_time="1" size="0x00008000"/>
   </dll_dependencies>
   <activities>
    <registry_activities>
     <reg_key_created name="HKLM\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000\Control"/>
     <reg_key_created name="HKLM\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000\Control"/>
     <reg_value_modified count="1" key="HKLM\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000\Control" value_data="RasMan" value_name="ActiveService"/>
     <reg_value_modified count="1" key="HKLM\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000\Control" value_data="TapiSrv" value_name="ActiveService"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0303\4&amp;2C5A7332&amp;0" value_data="{4D36E96B-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0400\4&amp;2C5A7332&amp;0" value_data="{4D36E978-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0501\1" value_data="{4D36E978-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0700\4&amp;2C5A7332&amp;0" value_data="{4D36E969-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0A03\1" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI\PNP0F13\4&amp;2C5A7332&amp;0" value_data="{4D36E96F-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ACPI_HAL\PNP0C08\0" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\DISPLAY\DEFAULT_MONITOR\4&amp;2946A9FF&amp;0&amp;11223344&amp;00&amp;02" value_data="{4D36E96E-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\IDE\CDROMQEMU_QEMU_CD-ROM________________________0.9.____\4D51303030302033202020202020202020202020" value_data="{4D36E965-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\IDE\DISKQEMU_HARDDISK___________________________0.9.1___\4D51303030302031202020202020202020202020" value_data="{4D36E967-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ISAPNP\READDATAPORT\0" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\LPTENUM\MICROSOFTRAWPORT\5&amp;34A37E9F&amp;0&amp;LPT1" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCIIDE\IDECHANNEL\4&amp;3DE75EA&amp;0&amp;0" value_data="{4D36E96A-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCIIDE\IDECHANNEL\4&amp;3DE75EA&amp;0&amp;1" value_data="{4D36E96A-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_1013&amp;DEV_00B8&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;10" value_data="{4D36E968-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_10EC&amp;DEV_8029&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;18" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_10EC&amp;DEV_8029&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;18" value_data="Realtek RTL8029(AS)-based Ethernet Adapter (Generic)" value_name="DeviceDesc"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_10EC&amp;DEV_8029&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;18" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}\0001" value_name="Driver"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_8086&amp;DEV_1237&amp;SUBSYS_00000000&amp;REV_02\3&amp;13C0B0C5&amp;0&amp;00" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_8086&amp;DEV_7000&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;08" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\PCI\VEN_8086&amp;DEV_7010&amp;SUBSYS_00000000&amp;REV_00\3&amp;13C0B0C5&amp;0&amp;09" value_data="{4D36E96A-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\ACPI_HAL\0000" value_data="{4D36E966-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\DMIO\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\FTDISK\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_AFD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_BEEP\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_DMBOOT\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_DMLOAD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_FIPS\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_GPC\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_HTTP\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_IPNAT\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_IPSEC\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_KSECDD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_MNMDD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_MOUNTMGR\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NDISTAPI\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NDISUIO\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NDIS\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NDPROXY\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NETBT\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_NULL\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_PARTMGR\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_PARVDM\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_RASACD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_RDPCDD\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_TCPIP\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_VGASAVE\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_VOLSNAP\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_WANARP\0000" value_data="{8ECC055D-047F-11D1-A537-0000F8753ED1}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MEDIA\MS_MMACM" value_data="{4D36E96C-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MEDIA\MS_MMDRV" value_data="{4D36E96C-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MEDIA\MS_MMMCI" value_data="{4D36E96C-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MEDIA\MS_MMVCD" value_data="{4D36E96C-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MEDIA\MS_MMVID" value_data="{4D36E96C-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_L2TPMINIPORT\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_NDISWANIP\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_NDISWANIP\0000" value_data="WAN Miniport (IP)" value_name="DeviceDesc"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_NDISWANIP\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}\0008" value_name="Driver"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_PPPOEMINIPORT\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_PPTPMINIPORT\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_PSCHEDMP\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_PSCHEDMP\0001" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\MS_PTIMINIPORT\0000" value_data="{4D36E972-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\RDPDR\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\RDP_KBD\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\RDP_MOU\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\SYSTEM\0000" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\SYSTEM\0001" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\ROOT\SYSTEM\0002" value_data="{4D36E97D-E325-11CE-BFC1-08002BE10318}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\ENUM\STORAGE\VOLUME\1&amp;30A96598&amp;0&amp;SIGNATURE95619561OFFSET7E00LENGTH13F291800" value_data="{71A27CDD-812A-11D0-BEC7-08002BE2092F}" value_name="ClassGUID"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\PlugPlay" value_data="3" value_name="PlugPlayServiceType"/>
     <reg_value_read count="3" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\RasMan\Enum" value_data="Root\LEGACY_RASMAN\0000" value_name="0"/>
     <reg_value_read count="6" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\RasMan\Enum" value_data="1" value_name="Count"/>
     <reg_value_read count="1" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\RpcSs\Enum" value_data="Root\LEGACY_RPCSS\0000" value_name="0"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\RpcSs\Enum" value_data="1" value_name="Count"/>
     <reg_value_read count="2" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TapiSrv\Enum" value_data="Root\LEGACY_TAPISRV\0000" value_name="0"/>
     <reg_value_read count="4" key="HKLM\SYSTEM\CONTROLSET001\SERVICES\TapiSrv\Enum" value_data="1" value_name="Count"/>
     <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\PlugPlay" value_data="LocalSystem" value_name="ObjectName"/>
     <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\RasMan" value_data="%SystemRoot%\system32\svchost.exe -k netsvcs" value_name="ImagePath"/>
     <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\RasMan" value_data="LocalSystem" value_name="ObjectName"/>
     <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\RpcSs" value_data="NT Authority\NetworkService" value_name="ObjectName"/>
     <reg_value_read count="1" key="HKLM\System\CurrentControlSet\Services\TapiSrv" value_data="%SystemRoot%\System32\svchost.exe -k netsvcs" value_name="ImagePath"/>
     <reg_value_read count="2" key="HKLM\System\CurrentControlSet\Services\TapiSrv" value_data="LocalSystem" value_name="ObjectName"/>
    </registry_activities>
    <file_activities>
     <file_modified description="file_modification_destruction" name="C:\PIPE_EVENTROOT\CIMV2SCM EVENT PROVIDER, Flags: Named pipe"/>
     <file_modified description="file_modification_destruction" name="C:\WINDOWS\system32\config\SysEvent.Evt"/>
     <file_modified description="file_modification_destruction" name="C:\ntsvcs, Flags: Named pipe"/>
     <file_read name="C:\ntsvcs, Flags: Named pipe"/>
     <fs_control_communication control_code="0x0011C017" count="2" file="C:\net\NtControlPipe4, Flags: Named pipe"/>
     <fs_control_communication control_code="0x0011001C" count="2" file="C:\ntsvcs, Flags: Named pipe"/>
    </file_activities>
   </activities>
  </analysis_subject>
  <global_network_activities>
   <udp_traffic>
    <unknown_udp_traffic>
     <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="111" res_bytes_sent="889" src_ip="192.168.0.2" src_port="1025" state="Normal establishment and termination"/>
     <udp_conversation dest_ip="192.168.0.1" dest_port="53" org_bytes_sent="37" res_bytes_sent="307" src_ip="192.168.0.2" src_port="1036" state="Normal establishment and termination"/>
    </unknown_udp_traffic>
   </udp_traffic>
  </global_network_activities>
 </analysis>
