<?xml version="1.0"?>
<!-- This analysis was created by CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="1.107" time="12.04.2007 20:51:35" file="764db083fa2bf511c982e7f1a66a7b15.exe" logpath="C:\analysis\log\764db083fa2bf511c982e7f1a66a7b15.exe\run_1\">
<calltree>
<process_call index="1" pid="888" filename="c:\764db083fa2bf511c982e7f1a66a7b15.exe" starttime="00:00.250" startreason="AnalysisTarget"><calltree>
<process_call index="2" pid="1112" filename="C:\WINDOWS\system32\dwwin.exe -x -s 1216" starttime="00:04.719" startreason="CreateProcess"/>
</calltree>
</process_call>

<process_call index="3" pid="684" filename="services.exe" starttime="00:27.031" startreason="SCM"/>
</calltree>

<processes>
<process index="1" pid="888" filename="c:\764db083fa2bf511c982e7f1a66a7b15.exe" filesize="40960" md5="764db083fa2bf511c982e7f1a66a7b15" username="nepenthes" parentindex="0" starttime="00:00.250" terminationtime="02:00.672" startreason="AnalysisTarget" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="3086">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="31862">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.10-34" signature_file_version="6.38.0.214">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\764db083fa2bf511c982e7f1a66a7b15.exe" successful="1" address="&#x24;400000" size="45056"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1" address="&#x24;77E50000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1" address="&#x24;77D10000" size="589824"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1" address="&#x24;77EF0000" size="290816"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1" address="&#x24;770F0000" size="573440"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1" address="&#x24;77BE0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1" address="&#x24;5D450000" size="630784"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1" address="&#x24;71A30000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1" address="&#x24;71A10000" size="94208"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1" address="&#x24;71A00000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1" address="&#x24;5E490000" size="53248"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1" address="&#x24;76AD0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1" address="&#x24;590B0000" size="28672"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
<load_dll dll="SHLWAPI.dll" successful="1" address="&#x24;77F40000" size="483328"/>
<load_dll dll="VERSION.dll" successful="1" address="&#x24;77BD0000" size="32768"/>
<load_dll dll="shell32.dll" successful="1" address="&#x24;7C9D0000" size="8515584"/>
</dll_handling_section>
<filesystem_section>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="C:\DOKUME&#x7E;1\NEPENT&#x7E;1\LOKALE&#x7E;1\Temp\2cd1_appcompat.txt" creationdistribution="CREATE_NEW" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="C:\DOKUME&#x7E;1\NEPENT&#x7E;1\LOKALE&#x7E;1\Temp\2cd1_appcompat.txt" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\&#x2A;" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\advapi32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="advapi32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\advapi32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\gdi32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="gdi32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\gdi32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\kernel32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="kernel32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\kernel32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ntdll.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="ntdll.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ntdll.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ole32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="ole32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ole32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\oleaut32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="oleaut32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\oleaut32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\shell32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="shell32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\shell32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\user32.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="user32.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\user32.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\wininet.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="wininet.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\wininet.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\winsock.dll" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="winsock.dll" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\winsock.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\dwwin.exe" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="dwwin.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Policies\Microsoft\PCHealth\ErrorReporting"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\PCHealth\ErrorReporting"/>
<delete_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DW"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DW"/>
<delete_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWFileTreeRoot"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DoReport"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ShowUI"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="AllOrNone"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeMicrosoftApps"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeWindowsApps"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DoTextLog"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeKernelFaults"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeShutdownErrs"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="NumberOfFaultPipes"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="NumberOfHangPipes"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="MaxUserQueueSize"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ForceQueueMode"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ExclusionList"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="InclusionList"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\Setup"/>
<query_value key="HKEY_LOCAL_MACHINE\System\Setup" subkey_or_value="SystemSetupInProgress"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\ExclusionList" subkey_or_value="764db083fa2bf511c982e7f1a66a7b15.exe"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\WPA\TabletPC"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\WPA\MediaCenter"/>
<query_value key="HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_CURRENT_USERS" subkey_or_value="S-1-5-21-1645522239-706699826-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\dwwin.exe"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"/>
<open_key key="HKEY_CURRENT_USERS" subkey_or_value="S-1-5-21-1645522239-706699826-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"/>
</registry_section>
<process_section>
<enum_modules targetpid="888" showwindow="SW_HIDE" apifunction="RtlQueryProcessDebugInformation"/>
<enum_modules targetpid="888" showwindow="SW_HIDE" apifunction="Module32FirstW"/>
<create_process commandline="C:\WINDOWS\system32\dwwin.exe -x -s 1216" targetpid="1112" creationflags="CREATE_DEFAULT_ERROR_MODE" showwindow="SW_HIDE" apifunction="CreateProcessW" successful="1"/>
</process_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
<user_section>
<revert_to_self tokenhandle="0"/>
</user_section>
</process>
<process index="2" pid="1112" filename="C:\WINDOWS\system32\dwwin.exe -x -s 1216" filesize="180224" md5="6e6fc9e91e7db4027b9bc34e73f00c69" username="nepenthes" parentindex="1" starttime="00:04.719" terminationtime="02:00.672" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="3086">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="31862">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.10-34" signature_file_version="6.38.0.214">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\dwwin.exe" successful="1" address="&#x24;30000000" size="212992"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1" address="&#x24;7C910000" size="749568"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1" address="&#x24;7C800000" size="1073152"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.DLL" successful="1" address="&#x24;77DA0000" size="696320"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1" address="&#x24;77E50000" size="593920"/>
<load_dll dll="C:\WINDOWS\system32\COMCTL32.DLL" successful="1" address="&#x24;5D450000" size="630784"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1" address="&#x24;77EF0000" size="290816"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1" address="&#x24;77D10000" size="589824"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.DLL" successful="1" address="&#x24;770F0000" size="573440"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1" address="&#x24;77BE0000" size="360448"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="C:\WINDOWS\system32\SHELL32.DLL" successful="1" address="&#x24;7C9D0000" size="8515584"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1" address="&#x24;77F40000" size="483328"/>
<load_dll dll="C:\WINDOWS\system32\URLMON.DLL" successful="1" address="&#x24;7DF20000" size="655360"/>
<load_dll dll="C:\WINDOWS\system32\VERSION.dll" successful="1" address="&#x24;77BD0000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\WININET.DLL" successful="1" address="&#x24;77180000" size="684032"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1" address="&#x24;77A50000" size="610304"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1" address="&#x24;77AF0000" size="73728"/>
<load_dll dll="C:\WINDOWS\system32\ShimEng.dll" successful="1" address="&#x24;5CF00000" size="155648"/>
<load_dll dll="C:\WINDOWS\AppPatch\AcGenral.DLL" successful="1" address="&#x24;6FD90000" size="1875968"/>
<load_dll dll="C:\WINDOWS\system32\WINMM.dll" successful="1" address="&#x24;76AF0000" size="188416"/>
<load_dll dll="C:\WINDOWS\system32\MSACM32.dll" successful="1" address="&#x24;77BB0000" size="86016"/>
<load_dll dll="C:\WINDOWS\system32\USERENV.dll" successful="1" address="&#x24;76620000" size="741376"/>
<load_dll dll="C:\WINDOWS\system32\UxTheme.dll" successful="1" address="&#x24;5B0F0000" size="229376"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1" address="&#x24;773A0000" size="1060864"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1" address="&#x24;71A30000" size="40960"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1" address="&#x24;71A10000" size="94208"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1" address="&#x24;71A00000" size="32768"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1" address="&#x24;5E490000" size="53248"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1" address="&#x24;76AD0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1" address="&#x24;590B0000" size="28672"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
<load_dll dll="uxtheme.dll" successful="1" address="&#x24;5B0F0000" size="229376"/>
<load_dll dll="imm32.dll" successful="1" address="&#x24;76330000" size="118784"/>
<load_dll dll="ole32.dll" successful="1" address="&#x24;774B0000" size="1298432"/>
<load_dll dll="riched20.dll" successful="1" address="&#x24;74DB0000" size="442368"/>
<load_dll dll="shfolder.dll" successful="1" address="&#x24;76730000" size="36864"/>
<load_dll dll="shell32.dll" successful="1" address="&#x24;7C9D0000" size="8515584"/>
<load_dll dll="PSAPI.DLL" successful="1" address="&#x24;76BB0000" size="45056"/>
<load_dll dll="C:\WINDOWS\system32\1031\dwintl.dll" successful="1" address="&#x24;314C0000" size="49152"/>
<load_dll dll="comctl32.dll" successful="1" address="&#x24;773A0000" size="1060864"/>
<load_dll dll="RASAPI32.DLL" successful="1" address="&#x24;76EA0000" size="245760"/>
<load_dll dll="RTUTILS.DLL" successful="1" address="&#x24;76E40000" size="57344"/>
<load_dll dll="RASMAN.DLL" successful="1" address="&#x24;76E50000" size="73728"/>
<load_dll dll="secur32.dll" successful="1" address="&#x24;77FC0000" size="69632"/>
<load_dll dll="C:\WINDOWS\system32\msv1_0.dll" successful="1" address="&#x24;77C40000" size="143360"/>
<load_dll dll="SHELL32.dll" successful="1" address="&#x24;7C9D0000" size="8515584"/>
<load_dll dll="USERENV.dll" successful="1" address="&#x24;76620000" size="741376"/>
<load_dll dll="netapi32.dll" successful="1" address="&#x24;597D0000" size="344064"/>
<load_dll dll="shlwapi.dll" successful="1" address="&#x24;77F40000" size="483328"/>
</dll_handling_section>
<filesystem_section>
<get_file_attributes filetype="File" srcfile="C:\DOKUME&#x7E;1\NEPENT&#x7E;1\LOKALE&#x7E;1\Temp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="C:\DOKUME&#x7E;1\NEPENT&#x7E;1\LOKALE&#x7E;1\Temp\14849F.dmp" creationdistribution="CREATE_NEW" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_TEMPORARY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\ROUTER" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Tcp" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\\.\Ip" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\nepenthes\Anwendungsdaten\Microsoft\Network\Connections\Pbk\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<ini_file_section>
<read_value file="WIN.INI" section="windows" value="ScrollInset"/>
<read_value file="WIN.INI" section="windows" value="DragDelay"/>
<read_value file="WIN.INI" section="windows" value="DragMinDist"/>
<read_value file="WIN.INI" section="windows" value="ScrollDelay"/>
<read_value file="WIN.INI" section="windows" value="ScrollInterval"/>
<read_value file="WIN.INI" section="richedit30" value="flags"/>
</ini_file_section>
<mutex_section>
<create_mutex name="CTF.LBES.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Compart.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Asm.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Layouts.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TMD.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TimListCache.FMPDefaultS-1-5-21-1645522239-706699826-839522115-1003MUTEX.DefaultS-1-5-21-16455222" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
<create_mutex name="MSCTF.Shared.MUTEX.MHG" owned="0"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Microsoft\Office\10.0\Common\Debug"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\OASys\OAClient"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Office\10.0\Common\InstallRoot"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\Compatibility\dwwin.exe"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\SystemShared\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared\" subkey_or_value="CUAS"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Keyboard Layout\Toggle"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Language Hotkey"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Layout Hotkey"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\" subkey_or_value="EnableAnchorContext"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion" subkey_or_value="DigitalProductId"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Microsoft\Internet Explorer\Settings"/>
<query_value key="HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings" subkey_or_value="Anchor Color"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\PCHealth\ErrorReporting\DW"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="BuildPipeMachine"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="Debug"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWFileTreeRoot"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWTracking"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWNoExternalURL"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWNoFileCollection"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWNoSecondLevelCollection"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWURLLaunch"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWNeverUpload"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWReporteeName"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWNoCollectionLink"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWAllowHeadless"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Policies\Microsoft\PCHealth\ErrorReporting\DW"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AeDebug"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug" subkey_or_value="Debugger"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Rpc\SecurityService"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="10"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders" subkey_or_value="SecurityProviders"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\Lsa\SspiCache"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msapsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="digest.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msnsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<enum_values key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="SOFTWARE\Microsoft\CTF\LangBarAddIn\"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\LangBarAddIn\"/>
</registry_section>
<process_section>
<enum_modules targetpid="888" showwindow="SW_HIDE" apifunction="RtlQueryProcessDebugInformation"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_system_directory/>
<get_computer_name/>
</system_info_section>
<user_section>
<impersonate_user user="nepenthes" tokenhandle="452"/>
</user_section>
<virtual_memory_section>
<vm_read targetpid="888" address="&#x24;0012FB78" size="8"/>
<vm_read targetpid="888" address="&#x24;0012FC6C" size="80"/>
<vm_read targetpid="888" address="&#x24;0012FC88" size="716"/>
<vm_read targetpid="888" address="&#x24;7FFDD000" size="28"/>
<vm_read targetpid="888" address="&#x24;7C91EB14" size="256"/>
<vm_read targetpid="888" address="&#x24;7FFDC000" size="28"/>
</virtual_memory_section>
<window_section>
<enum_window/>
<find_window classname="Shell_TrayWnd"/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
</connection>
</connections_unknown>
</winsock_section>

</process>
<process index="3" pid="684" filename="services.exe" filesize="108544" md5="edb6b81761bd60f32f740bbc40afb676" username="SYSTEM" parentindex="0" starttime="00:27.031" terminationtime="02:00.406" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
</process>
</processes>
</analysis>
