<?xml version="1.0"?>
<!-- This analysis was created by CWSandbox (c) Carsten Willems 2006-->
<analysis cwsversion="1.86" time="13.12.2006 01:27:41" file="a07a0a134f3c108d154ce8675be7c7e3.exe" logpath="c:\analysis\log\a07a0a134f3c108d154ce8675be7c7e3.exe\run_1\">
<calltree>
<process_call filename="c:\a07a0a134f3c108d154ce8675be7c7e3.exe" starttime="00:00.110" startreason="AnalysisTarget"><calltree>
<process_call filename="c:\sxe11.tmp" starttime="00:11.328" startreason="CreateProcess"><calltree>
<process_call filename="C:\WINDOWS\svchost.exe" starttime="00:48.610" startreason="CreateProcess"><calltree>
<process_call filename="C:\WINDOWS\sxe14.tmp" starttime="00:51.000" startreason="CreateProcess"/>
</calltree>
</process_call>

</calltree>
</process_call>

</calltree>
</process_call>

<process_call filename="services.exe" starttime="00:14.235" startreason="SCM"/>
</calltree>

<processes>
<process index="1" pid="1116" filename="c:\a07a0a134f3c108d154ce8675be7c7e3.exe" filesize="356352" md5="a07a0a134f3c108d154ce8675be7c7e3" username="nepenthes" parentindex="0" starttime="00:00.110" terminationtime="01:31.266" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="2325">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="338398">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.9-18" signature_file_version="6.37.0.12">
<classification>TR/Proxy.Delf.BS.76</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\a07a0a134f3c108d154ce8675be7c7e3.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\LZ32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="c:\sxeF.tmp" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_file filetype="File" srcfile="c:\sxe10.tmp" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="c:\sxe10.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="c:\sxe11.tmp" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="c:\sxeF.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\sxe11.tmp" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="sxe11.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="c:\sxe11.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\WPA\TabletPC"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\WPA\MediaCenter"/>
<query_value key="HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_CURRENT_USERS" subkey_or_value="S-1-5-21-1645522239-706699826-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sxe11.tmp"/>
</registry_section>
<process_section>
<create_process commandline="&quot;c:\sxe11.tmp&quot; " targetpid="1132" showwindow="SW_HIDE" apifunction="CreateProcessA" successful="1"/>
<kill_process targetpid="1116" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
</process>
<process index="2" pid="1132" filename="c:\sxe11.tmp" filesize="683520" md5="ed126427c48e17d3cc57991c54583480" username="nepenthes" parentindex="1" starttime="00:11.328" terminationtime="01:30.953" startreason="CreateProcess" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="2325">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="338398">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.9-18" signature_file_version="6.37.0.12">
<classification>OK</classification>
<additional_info/>
</scanner>

</virusscan_section>
<com_section>
<com_create_instance inprocserver32="C:\Programme\Messenger\msgsc.dll" progid="Messenger.UIAutomation.1" interfaceid="{00000000-0000-0000-C000-000000000046}"/>
<com_create_instance inprocserver32="C:\Programme\Messenger\msgsc.dll" progid="MessengerNative.UIAutomation.1" interfaceid="{00000000-0000-0000-C000-000000000046}"/>
<com_create_instance inprocserver32="C:\Programme\Messenger\msgsc.dll" progid="MessengerNative.UIAutomation.1" interfaceid="{D50C3386-0F89-48F8-B204-3604629DEE10}"/>
<com_get_class_object inprocserver32="oleaut32.dll" interfaceid="{D5F569D0-593B-101A-B569-08002B2DBF7A}"/>
<com_create_instance inprocserver32="C:\Programme\Messenger\msgsc.dll" progid="MessengerPrivateNative.MessengerPriv.1" interfaceid="{00000000-0000-0000-C000-000000000046}"/>
<com_create_instance inprocserver32="C:\Programme\Messenger\msgsc.dll" progid="MessengerPrivateNative.MessengerPriv.1" interfaceid="{D50C3386-0F89-48F8-B204-3604629DEE10}"/>
<com_create_instance inprocserver32="C:\Programme\Messenger\msmsgs.exe" progid="MessengerNative.MsgrSessionManager.1" interfaceid="{00000000-0000-0000-C000-000000000046}"/>
</com_section>
<dll_handling_section>
<load_dll dll="c:\sxe11.tmp" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\version.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wininet.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="c:\sxe11.DEU" successful="0"/>
<load_dll dll="c:\sxe11.DE" successful="0"/>
<load_dll dll="uxtheme.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="C:\Programme\Gemeinsame Dateien\System\wab32res.dll" successful="1"/>
<load_dll dll="C:\Programme\Gemeinsame Dateien\System\wab32.dll" successful="1"/>
<load_dll dll="WS2_32.DLL" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
<load_dll dll="RASMAN.DLL" successful="1"/>
<load_dll dll="secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msv1_0.dll" successful="1"/>
<load_dll dll="SHELL32.dll" successful="1"/>
<load_dll dll="USERENV.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="WININET.dll" successful="1"/>
<load_dll dll="VERSION.dll" successful="1"/>
<load_dll dll="SXS.DLL" successful="1"/>
<load_dll dll="OLE32" successful="1"/>
<load_dll dll="RPCRT4.dll" successful="1"/>
<load_dll dll="user32.dll" successful="1"/>
<load_dll dll="OLEAUT32" successful="1"/>
</dll_handling_section>
<filesystem_section>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\ROUTER" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Tcp" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\\.\Ip" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\nepenthes\Anwendungsdaten\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="C:\WINDOWS\svchost.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\svchost.exe" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="svchost.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\*.*" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\nepenthes\Dados de aplicativos\Microsoft\Address Book\nepenthes.wab" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="C:\WINDOWS\Registration" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\Registration\R000000000007.clb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Programme\Messenger\msmsgs.exe\3" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Programme\Messenger\msmsgs.exe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\stdole2.tlb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Programme\Messenger\msmsgs.exe\2" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="CTF.LBES.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Compart.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Asm.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Layouts.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TMD.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TimListCache.FMPDefaultS-1-5-21-1645522239-706699826-839522115-1003MUTEX.DefaultS-1-5-21-16455222" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
<create_mutex name="ZonesCounterMutex" owned="0"/>
<create_mutex name="ZonesCacheCounterMutex" owned="0"/>
<create_mutex name="ZonesLockedCacheCounterMutex" owned="0"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Borland\Locales"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Borland\Locales"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Borland\Delphi\Locales"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\Compatibility\sxe11.tmp"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\SystemShared\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared\" subkey_or_value="CUAS"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Keyboard Layout\Toggle"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Language Hotkey"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Layout Hotkey"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\" subkey_or_value="EnableAnchorContext"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\WAB\DLLPath"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\WAB\DLLPath"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Rpc\SecurityService"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="10"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders" subkey_or_value="SecurityProviders"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\Lsa\SspiCache"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msapsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="digest.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msnsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<enum_values key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="PROTOCOLS\Name-Space Handler\"/>
<enum_keys key="HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows\CurrentVersion\Internet Settings"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings" subkey_or_value="DisableImprovedZoneCheck"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\WPA\TabletPC"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\WPA\MediaCenter"/>
<query_value key="HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_CURRENT_USERS" subkey_or_value="S-1-5-21-1645522239-706699826-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\svchost.exe"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\Setup"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="TypeLib"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib" subkey_or_value="{E02AD29E-80F5-46C6-B416-9B3EBDDF057E}"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46C6-B416-9B3EBDDF057E}" subkey_or_value="1.0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46C6-B416-9B3EBDDF057E}\1.0" subkey_or_value="0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46C6-B416-9B3EBDDF057E}\1.0\0" subkey_or_value="win32"/>
<query_value key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46C6-B416-9B3EBDDF057E}\1.0\0" subkey_or_value="win32" data="C:\Programme\Messenger\msmsgs.exe\3"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\MessengerService\Clients"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Policies\Microsoft\Windows\Installer"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer" subkey_or_value="Debug"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\ProxyStubClsid32" data="{00020424-0000-0000-C000-000000000046}"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\Forward" data="_CHAR(0x01)_"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\TypeLib"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\TypeLib" data="{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\TypeLib" subkey_or_value="Version"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="TypeLib\{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}"/>
<enum_keys key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}"/>
<enum_keys key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}\1.0"/>
<query_value key="HKEY_CLASSES_ROOT\TypeLib\{E02AD29E-80F5-46c6-B416-9B3EBDDF057E}\1.0\0\win32" data="C:\Programme\Messenger\msmsgs.exe\3"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib" subkey_or_value="{00020430-0000-0000-C000-000000000046}"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}" subkey_or_value="2.0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0" subkey_or_value="0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0" subkey_or_value="win32"/>
<query_value key="HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0" subkey_or_value="win32" data="C:\WINDOWS\system32\stdole2.tlb"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Rpc"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc" subkey_or_value="UDTAlignmentPolicy"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{7C95459B-C8E7-4605-B641-45EB06866659}\ProxyStubClsid32" data="{00020424-0000-0000-C000-000000000046}"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{7C95459B-C8E7-4605-B641-45EB06866659}\Forward"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{7C95459B-C8E7-4605-B641-45EB06866659}\TypeLib"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{7C95459B-C8E7-4605-B641-45EB06866659}\TypeLib" data="{53CED51D-432B-45b2-A3E0-0CE2C24235D4}"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{7C95459B-C8E7-4605-B641-45EB06866659}\TypeLib" subkey_or_value="Version"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}"/>
<enum_keys key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}" subkey_or_value="1.0"/>
<enum_keys key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}\1.0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}\1.0" subkey_or_value="0"/>
<open_key key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}\1.0\0" subkey_or_value="win32"/>
<query_value key="HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}\1.0\0\win32" data="C:\Programme\Messenger\msmsgs.exe\2"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{36602AFA-4859-4DF5-820B-BF35ACAA16CA}\ProxyStubClsid32" data="{00020424-0000-0000-C000-000000000046}"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{36602AFA-4859-4DF5-820B-BF35ACAA16CA}\Forward"/>
<open_key key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{36602AFA-4859-4DF5-820B-BF35ACAA16CA}\TypeLib"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{36602AFA-4859-4DF5-820B-BF35ACAA16CA}\TypeLib" data="{53CED51D-432B-45b2-A3E0-0CE2C24235D4}"/>
<query_value key="HKEY_CLASSES_ROOT\Interface\{36602AFA-4859-4DF5-820B-BF35ACAA16CA}\TypeLib" subkey_or_value="Version"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\OleAut"/>
<query_value key="HKEY_CLASSES_ROOT" subkey_or_value="Interface\{D50C3386-0F89-48F8-B204-3604629DEE10}\Forward" data=","/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="SOFTWARE\Microsoft\MessengerService"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\MessengerService" subkey_or_value="RTCState"/>
<query_value key="HKEY_CURRENT_USER\SOFTWARE\Microsoft\MessengerService" subkey_or_value="ExchangeState"/>
</registry_section>
<process_section>
<create_process commandline="C:\Arquivos de Programas\Internet Explorer\Iexplore.exe http://www.humortadela.com.br" showwindow="SW_SHOWNORMAL" apifunction="WinExec" successful="0"/>
<create_process commandline="C:\WINDOWS\svchost.exe" showwindow="SW_HIDE" apifunction="WinExec" successful="1"/>
<kill_process targetpid="1132" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_system_directory/>
<get_computer_name/>
</system_info_section>
<user_section>
<impersonate_user user="nepenthes" tokenhandle="500"/>
<get_username tokenhandle="0"/>
</user_section>
<window_section>
<enum_window/>
<find_window classname="Shell_TrayWnd"/>
<destroy_window classname="TForm1" windowname="lo "/>
<destroy_window classname="tooltips_class32"/>
<destroy_window classname="TPUtilWindow"/>
<destroy_window classname="TApplication" windowname="sxe11"/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
</connection>
</connections_unknown>
<connections_udp>
<connection transportprotocol="UDP" connectionestablished="0" socket="-1">
</connection>
</connections_udp>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="210.58.101.241" remoteport="80" protocol="HTTP" connectionestablished="1" socket="452">
<http_data>
<http_cmd method="GET" url="/modules/xfsection/html/msmm.exe" http_version="HTTP/1.1"/>
</http_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
<process index="3" pid="664" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:14.235" terminationtime="02:00.469" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
</process>
<process index="4" pid="1640" filename="C:\WINDOWS\svchost.exe" filesize="914944" md5="76841d4594f0b5ef11f6f06f6b01ebcf" username="nepenthes" parentindex="2" starttime="00:48.610" terminationtime="02:00.250" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="2325">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="338398">
<classification>Generic.Banker.Delf.B2693D44</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.9-18" signature_file_version="6.37.0.12">
<classification>TR/Spy.Banker.GN.914944</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="C:\WINDOWS\svchost.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\LZ32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\sxe12.tmp" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_file filetype="File" srcfile="C:\WINDOWS\sxe13.tmp" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="C:\WINDOWS\sxe13.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_file filetype="File" srcfile="C:\WINDOWS\sxe14.tmp" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="C:\WINDOWS\sxe12.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\sysmain.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\SystemRoot\AppPatch\systest.sdb" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ATTRIBUTES" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\Device\NamedPipe\ShimViewer" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE,FILE_ADD_SUBDIRECTORY,FILE_APPEND_DATA,FILE_CREATE_PIPE_INSTANCE,FILE_WRITE_EA,FILE_WRITE_ATTRIBUTES" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\sxe14.tmp" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="sxe14.tmp" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\WPA\TabletPC"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\WPA\MediaCenter"/>
<query_value key="HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter" subkey_or_value="Installed"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_CURRENT_USERS" subkey_or_value="S-1-5-21-1645522239-706699826-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sxe14.tmp"/>
</registry_section>
<process_section>
<create_process commandline="&quot;C:\WINDOWS\sxe14.tmp&quot; " targetpid="1380" showwindow="SW_HIDE" apifunction="CreateProcessA" successful="1"/>
</process_section>
</process>
<process index="5" pid="1380" filename="C:\WINDOWS\sxe14.tmp" filesize="3816448" md5="3f352d591dedb24ce03fb3d0d63cb2c6" username="nepenthes" parentindex="4" starttime="00:51.000" terminationtime="02:00.610" startreason="CreateProcess" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
Error, empty file

</virusscan_section>
<dll_handling_section>
<load_dll dll="C:\WINDOWS\sxe14.tmp" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\version.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wininet.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\sxe14.DEU" successful="0"/>
<load_dll dll="C:\WINDOWS\sxe14.DE" successful="0"/>
<load_dll dll="uxtheme.dll" successful="1"/>
<load_dll dll="WS2_32.DLL" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
<load_dll dll="RASMAN.DLL" successful="1"/>
<load_dll dll="secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msv1_0.dll" successful="1"/>
<load_dll dll="SHELL32.dll" successful="1"/>
<load_dll dll="USERENV.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\ROUTER" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Tcp" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\Ip" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="\\.\Ip" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Connections\Pbk\rasphone.pbk" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Dokumente und Einstellungen\nepenthes\Anwendungsdaten\Microsoft\Network\Connections\Pbk\*.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="CTF.LBES.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Compart.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Asm.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.Layouts.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TMD.MutexDefaultS-1-5-21-1645522239-706699826-839522115-1003" owned="0"/>
<create_mutex name="CTF.TimListCache.FMPDefaultS-1-5-21-1645522239-706699826-839522115-1003MUTEX.DefaultS-1-5-21-16455222" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
<create_mutex name="MSCTF.Shared.MUTEX.EOF" owned="0"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Borland\Locales"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Borland\Locales"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Software\Borland\Delphi\Locales"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\Compatibility\sxe14.tmp"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\SystemShared\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared\" subkey_or_value="CUAS"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="Keyboard Layout\Toggle"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Language Hotkey"/>
<query_value key="HKEY_CURRENT_USER\Keyboard Layout\Toggle" subkey_or_value="Layout Hotkey"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\" subkey_or_value="EnableAnchorContext"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\Rpc\SecurityService"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="10"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders" subkey_or_value="SecurityProviders"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\Lsa\SspiCache"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msapsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="digest.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache" subkey_or_value="msnsspc.dll"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Name"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Comment"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Capabilities"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="RpcId"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Version"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="Type"/>
<query_value key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll" subkey_or_value="TokenSize"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<enum_values key="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="SOFTWARE\Microsoft\CTF\LangBarAddIn\"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\CTF\LangBarAddIn\"/>
</registry_section>
<process_section>
<create_process commandline="iexplore WWW_GetWindowInfo" showwindow="SW_SHOWMINNOACTIVE" apifunction="WinExec" successful="0"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_system_directory/>
<get_computer_name/>
</system_info_section>
<user_section>
<impersonate_user user="nepenthes" tokenhandle="512"/>
</user_section>
<window_section>
<enum_window/>
<find_window classname="Shell_TrayWnd"/>
<find_window classname="Shell DocObject View"/>
<find_window windowname="Evite que outras pessoas vejam você digitar sua senha - Microsoft Internet Explorer"/>
<find_window windowname="Evite que outras pessoas te vejam digitar a sua -senha- - Microsoft Internet Explorer"/>
<find_window windowname="A senha de oito dígitos é usada somente para o login - Microsoft Internet Explorer"/>
<find_window windowname="Não abra e-mail de origem desconhecida - Microsoft Internet Explorer"/>
<find_window windowname="Verifique um pequeno cadeado fechado na parte inferior do navegador - Microsoft Internet Explorer"/>
<find_window windowname="Verifique um pequeno cadeado na parte inferior de seu navegador - Microsoft Internet Explorer"/>
<find_window windowname="Evite que outras pessoas vejam você digitar a sua -senha- - Microsoft Internet Explorer"/>
<find_window windowname="Mantenha atualizado o sistema operacional, o navegador e o anti-vírus/trojan - Microsoft Internet Explorer"/>
<find_window windowname="Troque sua senha caso ela possa ser descoberta facilmente - Microsoft Internet Explorer"/>
<find_window windowname="Sempre consulte esta página para novas informações sobre a segurança - Microsoft Internet Explorer"/>
<find_window windowname="Sempre consulte esta página para novas informações sobre segurança - Microsoft Internet Explorer"/>
<find_window windowname="Evite realizar operações em equipamentos de uso público - Microsoft Internet Explorer"/>
<find_window windowname="Não permita que outras pessoas conheçam os seus dados de acesso - Microsoft Internet Explorer"/>
<find_window windowname="Escolha &quot;senhas&quot; diferentes do seu nascimento, CPF e n° seqüenciais - Microsoft Internet Explorer"/>
<find_window windowname="Note se no incio do campo &quot;endereço&quot; surgem as letras &quot;https&quot; - Microsoft Internet Explorer"/>
<find_window windowname="Não use atalhos em e-mail para acessar o site. Digite o endereço direto no navegador - Microsoft Internet Explorer"/>
<find_window windowname="Não abra arquivos de origem desconhecida - Microsoft Internet Explorer"/>
<find_window windowname="Evite abrir arquivos executáveis anexados às suas mensagens - Microsoft Internet Explorer"/>
<find_window windowname="Não faça alteração cadastral por e-mail - Microsoft Internet Explorer"/>
<find_window windowname="Não enviamos e-mail sem a sua permissão - Microsoft Internet Explorer"/>
<find_window windowname="Cuidado com links e downloads contidos em mensagens promocionais - Microsoft Internet Explorer"/>
<find_window windowname="Nunca digite seus dados de acesso em e-mail - Microsoft Internet Explorer"/>
<find_window windowname="Memorize suas senhas sem anotá-las - Microsoft Internet Explorer"/>
<find_window windowname="A senha de oito números somente é usada para o login - Microsoft Internet Explorer"/>
<find_window windowname="&gt;^bR_CHAR(0x0C)_^O	VV_CHAR(0x06)_NRÐEJOÿBLü&gt;;FHFö÷9A66B4µ&lt;îë=&gt;:.+2ä$5á,$2/_CHAR(0x1D)_.ÚÛ +*%'ÕÒÞÐü_CHAR(0x17)__CHAR(0x10)__CHAR(0x1E)__CHAR(0x1A)__CHAR(0x1D)__CHAR(0x18)__CHAR(0x0E)__CHAR(0x1B)_Æî_CHAR(0x12)__CHAR(0x17)__CHAR(0x07)__CHAR(0x13)__CHAR(0x0E)__CHAR(0x04)__CHAR(0x12)_½á_CHAR(0x13)_
_CHAR(0x05)__CHAR(0x07)_	û_CHAR(0x07)_"/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="gsmtp185.google.com" resulting_addr="64.233.185.27"/>
</connection>
</connections_unknown>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="64.233.185.27" remoteport="25" connectionestablished="0" socket="508">
</connection>
</connections_outgoing>
</winsock_section>

</process>
</processes>
</analysis>