<?xml version="1.0"?>
<!-- This analysis was created by CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="1.86" time="28.12.2006 12:43:38" file="b023f53b27eff3e3d70fd2bb39e15518.exe" logpath="c:\analysis\log\b023f53b27eff3e3d70fd2bb39e15518.exe\run_1\">
<calltree>
<process_call filename="c:\b023f53b27eff3e3d70fd2bb39e15518.exe" starttime="00:00.062" startreason="AnalysisTarget"><calltree>
<process_call filename="\&#x3F;&#x3F;\C:\WINDOWS\system32\winlogon.exe" starttime="00:02.016" startreason="InjectedCode"><calltree>
<process_call filename="C:\WINDOWS\system32\svchost.exe" starttime="00:03.547" startreason="InjectedCode"><calltree>
<process_call starttime="00:05.656" startreason="InjectedCode"/>
<process_call filename="C:\WINDOWS\system32\services.exe" starttime="00:05.719" startreason="InjectedCode"/>
<process_call filename="C:\WINDOWS\system32\lsass.exe" starttime="00:05.969" startreason="InjectedCode"/>
<process_call starttime="00:08.062" startreason="InjectedCode"/>
<process_call starttime="00:08.437" startreason="InjectedCode"/>
<process_call starttime="00:18.531" startreason="InjectedCode"/>
<process_call starttime="00:28.641" startreason="InjectedCode"/>
<process_call starttime="00:38.734" startreason="InjectedCode"/>
<process_call starttime="00:48.828" startreason="InjectedCode"/>
<process_call starttime="00:58.906" startreason="InjectedCode"/>
<process_call starttime="01:08.984" startreason="InjectedCode"/>
<process_call starttime="01:19.078" startreason="InjectedCode"/>
<process_call starttime="01:29.281" startreason="InjectedCode"/>
<process_call starttime="01:29.344" startreason="InjectedCode"/>
<process_call starttime="01:39.422" startreason="InjectedCode"/>
<process_call starttime="01:48.781" startreason="InjectedCode"/>
<process_call starttime="01:58.859" startreason="InjectedCode"/>
</calltree>
</process_call>

</calltree>
</process_call>

</calltree>
</process_call>

</calltree>

<processes>
<process index="1" pid="2044" filename="c:\b023f53b27eff3e3d70fd2bb39e15518.exe" filesize="32505" md5="b023f53b27eff3e3d70fd2bb39e15518" username="nepenthes" parentindex="0" starttime="00:00.062" terminationtime="00:03.609" startreason="AnalysisTarget" terminationreason="NormalTermination" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="2391">
<classification>OK</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="362459">
<classification>DeepScan:Generic.Malware.G!Sdldg.5BD379D9</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.9-20" signature_file_version="6.37.0.81">
<classification>TR/Agent.32505</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\b023f53b27eff3e3d70fd2bb39e15518.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="kernel32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="ntdll.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="wsock32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\ntos.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_ARCHIVE,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<delete_file filetype="File" srcfile="C:\WINDOWS\system32\ntos.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\b023f53b27eff3e3d70fd2bb39e15518.exe" dstfile="C:\WINDOWS\system32\ntos.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ntos.exe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="C:\WINDOWS\system32\ntdll.dll" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<set_file_time filetype="File" srcfile="C:\WINDOWS\system32\ntos.exe" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\ntos.exe" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_ARCHIVE,FILE_ATTRIBUTE_READONLY,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="__SYSTEM__91C38905__" owned="1"/>
<open_mutex name="__SYSTEM__64AD0625__" owned="1"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SYSTEM\CurrentControlSet\Services\crypt32\Performance"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="software\microsoft\windows nt\currentversion\winlogon"/>
<query_value key="HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon" subkey_or_value="userinit"/>
<set_value key="HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon" subkey_or_value="userinit" data="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,"/>
</registry_section>
<process_section>
<enum_processes showwindow="SW_HIDE" apifunction="Process32FirstW"/>
<open_process filename="C:\WINDOWS\system32\winlogon.exe" targetpid="488" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_QUERY_INFORMATION,PROCESS_VM_READ" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\winlogon.exe" targetpid="488" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<kill_process targetpid="2044" showwindow="SW_HIDE" apifunction="NtTerminateProcess"/>
</process_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
<thread_section>
<create_thread_remote targetpid="488" threadid="&#x24;00C4" address="&#x24;14D05AA2" parameteraddress="&#x24;00000000" creationflags="CREATE_SUSPENDED"/>
</thread_section>
<virtual_memory_section>
<vm_read targetpid="488" address="&#x24;7FFD7008" size="4"/>
<vm_read targetpid="488" address="&#x24;7FFD700C" size="4"/>
<vm_read targetpid="488" address="&#x24;00171EA4" size="4"/>
<vm_read targetpid="488" address="&#x24;00171EC0" size="80"/>
<vm_read targetpid="488" address="&#x24;00020534" size="74"/>
<vm_allocate targetpid="488" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="488" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="488" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="488" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="488" wantedaddress="&#x24;00000000" address="&#x24;01870000" wantedsize="1048576" size="1048576" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="488" wantedaddress="&#x24;0196E000" address="&#x24;0196E000" wantedsize="8192" size="8192" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="488" address="&#x24;0196E000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
</virtual_memory_section>
</process>
<process index="2" pid="488" filename="\&#x3F;&#x3F;\C:\WINDOWS\system32\winlogon.exe" filesize="-1" username="SYSTEM" parentindex="1" starttime="00:02.016" terminationtime="02:09.141" startreason="InjectedCode" terminationreason="Timeout" executionstatus="OK">
<dll_handling_section>
<load_dll dll="\&#x3F;&#x3F;\C:\WINDOWS\system32\winlogon.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\AUTHZ.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NDdeApi.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\PROFMAP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NETAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USERENV.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\PSAPI.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\REGAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SETUPAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\VERSION.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINSTA.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINTRUST.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\IMAGEHLP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSGINA.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHELL32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\COMCTL32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ODBC32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comdlg32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\odbcint.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHSVCS.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\sfc.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\sfc_os.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Apphelp.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINSCARD.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WTSAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\sxs.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\uxtheme.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINMM.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\cscdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WlNotify.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINSPOOL.DRV" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MPR.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\rsaenh.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SAMLIB.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\cscui.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\xpsp2res.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NTMARTA.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msv1_0.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\iphlpapi.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\COMRes.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CLBCATQ.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemprox.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemcomn.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wbem\wbemsvc.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wbem\fastprox.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSVCP60.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NTDSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="kernel32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="ntdll.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="wsock32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<set_file_attributes filetype="File" srcfile="C:\WINDOWS\system32\wsnpoem" desiredaccess="FILE_ANY_ACCESS" flags="FILE_ATTRIBUTE_HIDDEN,FILE_ATTRIBUTE_SYSTEM,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="C:\WINDOWS\system32\wsnpoem\video.dll" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="C:\WINDOWS\system32\wsnpoem\audio.dll" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_namedpipe filetype="namedpipe" srcfile="\\.\pipe\__SYSTEM__64AD0625__" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" namedpipeopenmode="PIPE_ACCESS_DUPLEX" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="__SYSTEM__64AD0625__" owned="0"/>
<open_mutex name="__SYSTEM__7F4523E5__" owned="1"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="software\microsoft\windows nt\currentversion\winlogon"/>
<query_value key="HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon" subkey_or_value="userinit"/>
</registry_section>
<process_section>
<enum_processes showwindow="SW_HIDE" apifunction="Process32FirstW"/>
<open_process filename="C:\WINDOWS\system32\svchost.exe" targetpid="756" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_QUERY_INFORMATION,PROCESS_VM_READ" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\svchost.exe" targetpid="756" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
</process_section>
<system_info_section>
<get_system_directory/>
<get_system_time/>
</system_info_section>
<thread_section>
<create_thread_remote targetpid="756" threadid="&#x24;0540" address="&#x24;14D066CC" parameteraddress="&#x24;00000000" creationflags="CREATE_SUSPENDED"/>
</thread_section>
<user_section>
<revert_to_self tokenhandle="0"/>
</user_section>
<virtual_memory_section>
<vm_read targetpid="756" address="&#x24;7FFD7008" size="4"/>
<vm_read targetpid="756" address="&#x24;7FFD700C" size="4"/>
<vm_read targetpid="756" address="&#x24;00191EA4" size="4"/>
<vm_read targetpid="756" address="&#x24;00191EC0" size="80"/>
<vm_read targetpid="756" address="&#x24;00020598" size="64"/>
<vm_allocate targetpid="756" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="756" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="756" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="756" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="756" wantedaddress="&#x24;00000000" address="&#x24;005A0000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="756" wantedaddress="&#x24;005DA000" address="&#x24;005DA000" wantedsize="24576" size="24576" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="756" address="&#x24;005DA000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
</virtual_memory_section>
</process>
<process index="3" pid="756" filename="C:\WINDOWS\system32\svchost.exe" filesize="14336" md5="65a819b121eb6fdab4400ea42bdffe64" username="SYSTEM" parentindex="2" starttime="00:03.547" terminationtime="02:09.094" startreason="InjectedCode" terminationreason="Timeout" executionstatus="OK">
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\svchost.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ShimEng.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\AppPatch\AcGenral.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINMM.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSACM32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\VERSION.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHELL32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USERENV.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\UxTheme.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NTMARTA.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SAMLIB.dll" successful="1"/>
<load_dll dll="c:\windows\system32\rpcss.dll" successful="1"/>
<load_dll dll="c:\windows\system32\Secur32.dll" successful="1"/>
<load_dll dll="c:\windows\system32\WS2_32.dll" successful="1"/>
<load_dll dll="c:\windows\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\xpsp2res.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CLBCATQ.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\COMRes.dll" successful="1"/>
<load_dll dll="c:\windows\system32\termsrv.dll" successful="1"/>
<load_dll dll="c:\windows\system32\ICAAPI.dll" successful="1"/>
<load_dll dll="c:\windows\system32\SETUPAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINTRUST.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\IMAGEHLP.dll" successful="1"/>
<load_dll dll="c:\windows\system32\AUTHZ.dll" successful="1"/>
<load_dll dll="c:\windows\system32\mstlsapi.dll" successful="1"/>
<load_dll dll="c:\windows\system32\ACTIVEDS.dll" successful="1"/>
<load_dll dll="c:\windows\system32\adsldpc.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NETAPI32.dll" successful="1"/>
<load_dll dll="c:\windows\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\REGAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\rsaenh.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Apphelp.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="kernel32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="ntdll.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="wsock32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<create_namedpipe filetype="namedpipe" srcfile="\\.\pipe\__SYSTEM__7F4523E5__" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" namedpipeopenmode="PIPE_ACCESS_DUPLEX" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="__SYSTEM__7F4523E5__" owned="0"/>
<open_mutex name="__SYSTEM__91C38905__" owned="1"/>
<open_mutex name="0000000000000000000000042" owned="1"/>
<open_mutex name="0000000000000000000000041" owned="1"/>
<create_mutex name="0000000000000000000000041" owned="1"/>
<open_mutex name="64AEF76801C7029E000001642" owned="1"/>
<open_mutex name="64AEF76801C7029E000001641" owned="1"/>
<create_mutex name="64AEF76801C7029E000001641" owned="1"/>
<open_mutex name="657C01A401C7029E0000021C2" owned="1"/>
<open_mutex name="657C01A401C7029E0000021C1" owned="1"/>
<create_mutex name="657C01A401C7029E0000021C1" owned="1"/>
<open_mutex name="6587ED6601C7029E000002282" owned="1"/>
<open_mutex name="6587ED6601C7029E000002281" owned="1"/>
<create_mutex name="6587ED6601C7029E000002281" owned="1"/>
<open_mutex name="6635F91001C7029E0000039C2" owned="1"/>
<open_mutex name="6635F91001C7029E0000039C1" owned="1"/>
<create_mutex name="6635F91001C7029E0000039C1" owned="1"/>
<open_mutex name="66490BE001C7029E000003F82" owned="1"/>
<open_mutex name="66490BE001C7029E000003F81" owned="1"/>
<create_mutex name="66490BE001C7029E000003F81" owned="1"/>
<open_mutex name="6660E36401C7029E0000043C2" owned="1"/>
<open_mutex name="6660E36401C7029E0000043C1" owned="1"/>
<create_mutex name="6660E36401C7029E0000043C1" owned="1"/>
<open_mutex name="66BDDF1A01C7029E000004682" owned="1"/>
<open_mutex name="66BDDF1A01C7029E000004681" owned="1"/>
<create_mutex name="66BDDF1A01C7029E000004681" owned="1"/>
<open_mutex name="678624A201C7029E000005C42" owned="1"/>
<open_mutex name="678624A201C7029E000005C41" owned="1"/>
<create_mutex name="678624A201C7029E000005C41" owned="1"/>
<open_mutex name="67DBF94A01C7029E000006182" owned="1"/>
<open_mutex name="67DBF94A01C7029E000006181" owned="1"/>
<create_mutex name="67DBF94A01C7029E000006181" owned="1"/>
<open_mutex name="68A6A12C01C7029E000006942" owned="1"/>
<open_mutex name="68A6A12C01C7029E000006941" owned="1"/>
<create_mutex name="68A6A12C01C7029E000006941" owned="1"/>
<open_mutex name="6C37C5D201C7029E000007802" owned="1"/>
<open_mutex name="6C37C5D201C7029E000007801" owned="1"/>
<create_mutex name="6C37C5D201C7029E000007801" owned="1"/>
<open_mutex name="6EFE429601C7029E0000033C2" owned="1"/>
<open_mutex name="6EFE429601C7029E0000033C1" owned="1"/>
<create_mutex name="6EFE429601C7029E0000033C1" owned="1"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="software\microsoft\windows nt\currentversion\network"/>
<query_value key="HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\network" subkey_or_value="UID"/>
<set_value key="HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\network" subkey_or_value="UID" data="RANDOM_01099EE6"/>
</registry_section>
<process_section>
<enum_processes showwindow="SW_HIDE" apifunction="Process32FirstW"/>
<open_process targetpid="4" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="\SystemRoot\System32\smss.exe" targetpid="356" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\services.exe" targetpid="540" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\lsass.exe" targetpid="552" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\svchost.exe" targetpid="924" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\System32\svchost.exe" targetpid="1016" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\svchost.exe" targetpid="1084" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\svchost.exe" targetpid="1128" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\Explorer.EXE" targetpid="1476" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\spoolsv.exe" targetpid="1560" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\ctfmon.exe" targetpid="1684" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\system32\wdfmgr.exe" targetpid="1920" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process filename="C:\WINDOWS\System32\alg.exe" targetpid="828" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
<open_process targetpid="1084" desiredaccess="PROCESS_ALL_ACCESS,PROCESS_CREATE_THREAD,PROCESS_QUERY_INFORMATION,PROCESS_VM_OPERATION,PROCESS_VM_READ,PROCESS_VM_WRITE" showwindow="SW_HIDE" apifunction="NtOpenProcess" successful="1"/>
</process_section>
<system_info_section>
<get_computer_name/>
<get_system_time/>
</system_info_section>
<thread_section>
<create_thread_remote targetpid="356" threadid="&#x24;04D8" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="540" threadid="&#x24;077C" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="552" threadid="&#x24;0350" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="924" threadid="&#x24;03D8" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1016" threadid="&#x24;009C" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1084" threadid="&#x24;07C0" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1128" threadid="&#x24;05F8" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1476" threadid="&#x24;03E4" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1560" threadid="&#x24;0570" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1684" threadid="&#x24;010C" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1920" threadid="&#x24;0518" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="828" threadid="&#x24;0544" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="356" threadid="&#x24;0534" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1016" threadid="&#x24;03E8" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1128" threadid="&#x24;030C" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1476" threadid="&#x24;00F0" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1560" threadid="&#x24;02E0" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1684" threadid="&#x24;0358" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="1920" threadid="&#x24;0364" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
<create_thread_remote targetpid="828" threadid="&#x24;020C" address="&#x24;14D04F5C" parameteraddress="&#x24;14D00000" creationflags="CREATE_SUSPENDED"/>
</thread_section>
<virtual_memory_section>
<vm_allocate targetpid="4" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="4" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="4" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="4" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="4" wantedaddress="&#x24;00000000" address="&#x24;00170000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="4" wantedaddress="&#x24;001AB000" address="&#x24;001AB000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="4" address="&#x24;001AB000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="356" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="356" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="356" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="356" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="356" wantedaddress="&#x24;00000000" address="&#x24;00300000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="356" wantedaddress="&#x24;0033B000" address="&#x24;0033B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="356" address="&#x24;0033B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="540" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="540" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="540" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="540" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="540" wantedaddress="&#x24;00000000" address="&#x24;00040000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="540" wantedaddress="&#x24;0007B000" address="&#x24;0007B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="540" address="&#x24;0007B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="552" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="552" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="552" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="552" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="552" wantedaddress="&#x24;00000000" address="&#x24;00AE0000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="552" wantedaddress="&#x24;00B1B000" address="&#x24;00B1B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="552" address="&#x24;00B1B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="924" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="924" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="924" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="924" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="924" wantedaddress="&#x24;00000000" address="&#x24;006A0000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="924" wantedaddress="&#x24;006DB000" address="&#x24;006DB000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="924" address="&#x24;006DB000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1016" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1016" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1016" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1016" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1016" wantedaddress="&#x24;00000000" address="&#x24;016D0000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1016" wantedaddress="&#x24;0170B000" address="&#x24;0170B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1016" address="&#x24;0170B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1084" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1084" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1084" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1084" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1084" wantedaddress="&#x24;00000000" address="&#x24;00800000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1084" wantedaddress="&#x24;0083B000" address="&#x24;0083B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1084" address="&#x24;0083B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1128" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1128" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1128" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1128" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1128" wantedaddress="&#x24;00000000" address="&#x24;00980000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1128" wantedaddress="&#x24;009BB000" address="&#x24;009BB000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1128" address="&#x24;009BB000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1476" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1476" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1476" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1476" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1476" wantedaddress="&#x24;00000000" address="&#x24;02480000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1476" wantedaddress="&#x24;024BB000" address="&#x24;024BB000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1476" address="&#x24;024BB000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1560" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1560" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1560" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1560" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1560" wantedaddress="&#x24;00000000" address="&#x24;00960000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1560" wantedaddress="&#x24;0099B000" address="&#x24;0099B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1560" address="&#x24;0099B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1684" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1684" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1684" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1684" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1684" wantedaddress="&#x24;00000000" address="&#x24;00950000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1684" wantedaddress="&#x24;0098B000" address="&#x24;0098B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1684" address="&#x24;0098B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="1920" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="1920" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="1920" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="1920" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="1920" wantedaddress="&#x24;00000000" address="&#x24;00600000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="1920" wantedaddress="&#x24;0063B000" address="&#x24;0063B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="1920" address="&#x24;0063B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
<vm_allocate targetpid="828" wantedaddress="&#x24;14D00000" address="&#x24;14D00000" wantedsize="77824" size="77824" protect="PAGE_EXECUTE_READWRITE" allocationtype="MEM_COMMIT,MEM_RESERVE"/>
<vm_protect targetpid="828" address="&#x24;14D00000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D00000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D01000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D01000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D02000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D02000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D03000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D03000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D04000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D04000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D05000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D05000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D06000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D06000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D07000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D07000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D08000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D08000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D09000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D09000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0A000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0A000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0B000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0B000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0C000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0C000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0D000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0D000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0E000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0E000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D0F000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D0F000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D10000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D10000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D11000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D11000" size="4096"/>
<vm_protect targetpid="828" address="&#x24;14D12000" wantedsize="4096" size="4096" protect="PAGE_EXECUTE_READWRITE"/>
<vm_write targetpid="828" address="&#x24;14D12000" size="4096"/>
<vm_allocate targetpid="828" wantedaddress="&#x24;00000000" address="&#x24;00630000" wantedsize="262144" size="262144" protect="PAGE_READWRITE" allocationtype="MEM_RESERVE"/>
<vm_allocate targetpid="828" wantedaddress="&#x24;0066B000" address="&#x24;0066B000" wantedsize="20480" size="20480" protect="PAGE_READWRITE" allocationtype="MEM_COMMIT"/>
<vm_protect targetpid="828" address="&#x24;0066B000" wantedsize="4096" size="4096" protect="PAGE_READWRITE,PAGE_GUARD"/>
</virtual_memory_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
</connection>
</connections_unknown>
</winsock_section>

</process>
<process index="4" pid="356" filesize="-1" parentindex="3" starttime="00:05.656" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="5" pid="540" filename="C:\WINDOWS\system32\services.exe" filesize="108544" md5="edb6b81761bd60f32f740bbc40afb676" username="SYSTEM" parentindex="3" starttime="00:05.719" terminationtime="02:09.359" startreason="InjectedCode" terminationreason="Timeout" executionstatus="OK">
</process>
<process index="6" pid="552" filename="C:\WINDOWS\system32\lsass.exe" filesize="13312" md5="183805eb05bca5a1e4aaaed4d2be3690" username="SYSTEM" parentindex="3" starttime="00:05.969" terminationtime="02:09.109" startreason="InjectedCode" terminationreason="Timeout" executionstatus="OK">
<dll_handling_section>
<load_dll dll="C:\WINDOWS\system32\lsass.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ADVAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\LSASRV.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MPR.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USER32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NETAPI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\NTDSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SAMLIB.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SAMSRV.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\cryptdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ShimEng.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\AppPatch\AcGenral.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINMM.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\OLEAUT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSACM32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\VERSION.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHELL32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\USERENV.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\UxTheme.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msprivs.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kerberos.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msv1_0.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\iphlpapi.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\netlogon.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\w32time.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSVCP60.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\schannel.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wdigest.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\rsaenh.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\scecli.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SETUPAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ipsecsvc.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\AUTHZ.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oakley.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WINIPSEC.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\hnetcfg.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\wshtcpip.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorsvc.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\psbase.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\dssenh.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="kernel32.dll" successful="1"/>
<load_dll dll="advapi32.dll" successful="1"/>
<load_dll dll="psapi.dll" successful="1"/>
<load_dll dll="shlwapi.dll" successful="1"/>
<load_dll dll="ntdll.dll" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="wininet.dll" successful="1"/>
<load_dll dll="wsock32.dll" successful="1"/>
<load_dll dll="ws2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\faultrep.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<open_file filetype="namedpipe" srcfile="\\.\pipe\PCHFaultRepExecPipe" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_namedpipe filetype="namedpipe" srcfile="\\.\PIPE\lsass" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="6587ED6601C7029E000002282" owned="1"/>
</mutex_section>
<registry_section>
<open_key key="HKEY_LOCAL_MACHINE\SECURITY" subkey_or_value="Policy"/>
<open_key key="HKEY_LOCAL_MACHINE\SECURITY\Policy" subkey_or_value="SecDesc"/>
<query_value key="HKEY_LOCAL_MACHINE\SECURITY\Policy\SecDesc"/>
<open_key key="HKEY_CURRENT_USER" subkey_or_value="software\microsoft\windows nt\currentversion\network"/>
<query_value key="HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\network" subkey_or_value="UID"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Policies\Microsoft\PCHealth\ErrorReporting"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="Software\Microsoft\PCHealth\ErrorReporting"/>
<delete_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DW"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DW"/>
<delete_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\DW" subkey_or_value="DWFileTreeRoot"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DoReport"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ShowUI"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="AllOrNone"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeMicrosoftApps"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeWindowsApps"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="DoTextLog"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeKernelFaults"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="IncludeShutdownErrs"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="NumberOfFaultPipes"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="NumberOfHangPipes"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="MaxUserQueueSize"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ForceQueueMode"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="ExclusionList"/>
<open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting" subkey_or_value="InclusionList"/>
<open_key key="HKEY_LOCAL_MACHINE" subkey_or_value="System\Setup"/>
<query_value key="HKEY_LOCAL_MACHINE\System\Setup" subkey_or_value="SystemSetupInProgress"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\ErrorReporting\ExclusionList" subkey_or_value="lsass.exe"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Groups\000003EB"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Aliases\000003EB"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Users\000003EB"/>
<query_value key="HKEY_LOCAL_MACHINE\SAM\SAM\DOMAINS\Account\Users\000003EB" subkey_or_value="V"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Groups\Names\nepenthes"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Aliases\Names\nepenthes"/>
<open_key key="HKEY_LOCAL_MACHINE\SAM\SAM" subkey_or_value="DOMAINS\Account\Users\Names\nepenthes"/>
<query_value key="HKEY_LOCAL_MACHINE\SAM\SAM\DOMAINS\Account\Users\Names\nepenthes"/>
</registry_section>
<process_section>
<enum_modules targetpid="552" showwindow="SW_HIDE" apifunction="EnumProcessModules"/>
</process_section>
<system_info_section>
<get_system_directory/>
</system_info_section>
<user_section>
<revert_to_self tokenhandle="0"/>
</user_section>
</process>
<process index="7" pid="924" filesize="-1" parentindex="3" starttime="00:08.062" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="8" pid="1016" filesize="-1" parentindex="3" starttime="00:08.437" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="9" pid="1084" filesize="-1" parentindex="3" starttime="00:18.531" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="10" pid="1128" filesize="-1" parentindex="3" starttime="00:28.641" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="11" pid="1476" filesize="-1" parentindex="3" starttime="00:38.734" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="12" pid="1560" filesize="-1" parentindex="3" starttime="00:48.828" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="13" pid="1684" filesize="-1" parentindex="3" starttime="00:58.906" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="14" pid="1920" filesize="-1" parentindex="3" starttime="01:08.984" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="15" pid="828" filesize="-1" parentindex="3" starttime="01:19.078" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="16" pid="356" filesize="-1" parentindex="3" starttime="01:29.281" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="17" pid="1016" filesize="-1" parentindex="3" starttime="01:29.344" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="18" pid="1128" filesize="-1" parentindex="3" starttime="01:39.422" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="19" pid="1476" filesize="-1" parentindex="3" starttime="01:48.781" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
<process index="20" pid="1560" filesize="-1" parentindex="3" starttime="01:58.859" terminationtime="00:00.000" startreason="InjectedCode" terminationreason="Unknown" executionstatus="CouldNotInstallHook">
</process>
</processes>
</analysis>
