<?xml version="1.0" encoding="windows-1251" ?>
<!-- AVZ XML Report -->
<AVZ Version="4.32" LogDate="11.11.2009 19:21:38" WinDir="C:\WINDOWS\" ProfileDir="C:\Documents and Settings\FallenAngel" IsWow64="False" CompHash="8EFD4DCB0381683DF31E412E7A534630">
 <PROCESS>
  <ITEM PID="1880" File="f:\проги\download master\dmaster.exe" CheckResult="-1" Descr="Download Master" LegalCopyright="2002-2009 WestByte" Hidden="0"  CmdLine="@quot;F:\проги\Download Master\dmaster.exe@quot; -autorun" Size="3778048" Attr="rsAh" CreateDate="29.08.2009 19:57:25" ChageDate="07.11.2009 0:50:36" MD5="B7A938C07891D3FAA2BDCB989BFCBD13" NationalName="Y" />
  <ITEM PID="1328" File="c:\windows\explorer.exe" CheckResult="0" Descr="Проводник" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Hidden="0"  CmdLine="C:\WINDOWS\Explorer.EXE" Size="1032704" Attr="rsAh" CreateDate="17.08.2004 17:04:48" ChageDate="17.08.2004 17:04:48" MD5="7637F34CBB1FD9076BDFB13F4EB72A1C" />
 </PROCESS>
 <DLL>
  <ITEM File="C:\PROGRA~1\SlySoft\GAMEJA~1\MAPLOM~1.DLL" CheckResult="-1"  Descr="Game Jackal"  LegalCopyright="Copyright 2007 SlySoft Inc."  UsedBy="1328" Hidden="0" Size="436736" Attr="rsAh" CreateDate="20.03.2009 23:44:56" ChageDate="31.07.2008 18:09:24" MD5="F91C71270D780FF1902A2F03C7F5D4C7" />
 </DLL>
 <KERNELOBJ>
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="A8D5F000" MemSize="018000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS" CheckResult="-1" Base="F7A01000" MemSize="002000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\FStarForce.sys" CheckResult="-1" Base="B9E69000" MemSize="007000" Descr="FStarForce" LegalCopyright="SNEG" Size="8704" Attr="rsAh" CreateDate="05.03.2009 16:36:41" ChageDate="22.01.2009 21:50:40" MD5="7DC18ECEA17FCBD0B8490EA4AB3CF4B2" />
  <ITEM File="spyr.sys" CheckResult="-1" Base="F74D6000" MemSize="100000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\yukonwxp.sys" CheckResult="-1" Base="B953E000" MemSize="02B000" Descr="NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter" LegalCopyright="© Copyright 2002-2003 Marvell ®. All rights reserved" Size="174464" Attr="rsAh" CreateDate="23.12.2003 5:32:00" ChageDate="23.12.2003 5:32:00" MD5="265B882E0501AC6D06F083B04AF488A8" />
 </KERNELOBJ>
 <Service>
  <ITEM File="clr_optimization_v2.0.50727_32" Name="clr_optimization_v2.0.50727_32" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="EhttpSrv.sys" Name="EhttpSrv" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="ekrn.sys" Name="ekrn" CheckResult="-1" Type="272" State="1"   />
  <ITEM File="FontCache3.0.0.0" Name="FontCache3.0.0.0" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="idsvc.sys" Name="idsvc" CheckResult="-1" Type="32" State="1"   />
  <ITEM File="MySQL.sys" Name="MySQL" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="NetTcpPortSharing.sys" Name="NetTcpPortSharing" CheckResult="-1" Type="32" State="1"   />
  <ITEM File="C:\WINDOWS\system32\GameMon.des" Name="npggsvc" CheckResult="-1" Type="272" State="1" Size="3171456" Attr="rsAh" CreateDate="29.07.2009 1:49:10" ChageDate="30.06.2009 0:55:50" MD5="086145977D79CCF779FDCC5F8286D2A4"  />
 </Service>
 <Drivers>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\FStarForce.sys" Name="FStarForce" CheckResult="-1" Type="1" State="4" Size="8704" Attr="rsAh" CreateDate="05.03.2009 16:36:41" ChageDate="22.01.2009 21:50:40" MD5="7DC18ECEA17FCBD0B8490EA4AB3CF4B2"  />
  <ITEM File="C:\WINDOWS\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="717296" Attr="rsAh" CreateDate="23.07.2008 18:43:55" ChageDate="18.02.2009 2:16:07" MD5=""  />
  <ITEM File="Abiosdsk.sys" Name="Abiosdsk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="abp480n5.sys" Name="abp480n5" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="adpu160m.sys" Name="adpu160m" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Aha154x.sys" Name="Aha154x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78u2.sys" Name="aic78u2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78xx.sys" Name="aic78xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="AliIde.sys" Name="AliIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="amsint.sys" Name="amsint" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc.sys" Name="asc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3350p.sys" Name="asc3350p" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3550.sys" Name="asc3550" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Atdisk.sys" Name="Atdisk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\atksgt.sys" Name="atksgt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="cd20xrnt.sys" Name="cd20xrnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Changer.sys" Name="Changer" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="CmdIde.sys" Name="CmdIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Cpqarray.sys" Name="Cpqarray" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dac960nt.sys" Name="dac960nt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dpti2o.sys" Name="dpti2o" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\Program Files\4GAME\LineageII\system\GameGuard\dump_wmimmc.sys" Name="dump_wmimmc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="EagleNT.sys" Name="EagleNT" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\ehdrv.sys" Name="ehdrv" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\epfwtdir.sys" Name="epfwtdir" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="hpn.sys" Name="hpn" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omgmt.sys" Name="i2omgmt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omp.sys" Name="i2omp" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ini910u.sys" Name="ini910u" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="lbrtfdc.sys" Name="lbrtfdc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="mraid35x.sys" Name="mraid35x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="npkcrypt.sys" Name="npkcrypt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PCIDump.sys" Name="PCIDump" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDCOMP.sys" Name="PDCOMP" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDFRAME.sys" Name="PDFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRELI.sys" Name="PDRELI" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRFRAME.sys" Name="PDRFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2.sys" Name="perc2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2hib.sys" Name="perc2hib" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1080.sys" Name="ql1080" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Ql10wnt.sys" Name="Ql10wnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql12160.sys" Name="ql12160" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1240.sys" Name="ql1240" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1280.sys" Name="ql1280" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Simbad.sys" Name="Simbad" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Sparrow.sys" Name="Sparrow" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\Drivers\StMp3Rec.sys" Name="StMp3Rec" CheckResult="-1" Type="1" State="1" Size="19840" Attr="rsAh" CreateDate="23.07.2008 18:06:37" ChageDate="04.01.2007 14:38:34" MD5="833AC40F6E7BE17951D6D9A956829547"  />
  <ITEM File="sym_hi.sys" Name="sym_hi" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="sym_u3.sys" Name="sym_u3" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc810.sys" Name="symc810" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc8xx.sys" Name="symc8xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="TosIde.sys" Name="TosIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ultra.sys" Name="ultra" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ViaIde.sys" Name="ViaIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="WDICA.sys" Name="WDICA" CheckResult="-1" Type="1" State="1"   />
 </Drivers>
 <AUTORUN>
  <ITEM File="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\Свернуть все окна.scf" CheckResult="-1" Enabled="1" Type="FILE" Size="101" Attr="rsAh" CreateDate="23.07.2008 13:14:44" ChageDate="05.06.2009 22:17:57" MD5="F8AD82976383A129C8E4F5D4962322B9" NationalName="Y" X1="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\Свернуть все окна.scf" X3="" />
  <ITEM File="C:\Program Files\1C\Oniblade\protect.exe;C:\Games\Oniblade\protect.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Oniblade" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\Bonjour\mDNSResponder.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\Borland\Delphi7\Bin\bordbg70.exe -aeargs %ld %ld" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\AeDebug" X3="Debugger" />
  <ITEM File="C:\Program Files\CDRoller\CDRoller.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="1875936" Attr="rsAh" CreateDate="26.03.2009 13:32:16" ChageDate="29.01.2009 14:18:40" MD5="D742EC6B6F3366766CD20C39162E8377" X1="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\CDRoller.lnk" X3="" />
  <ITEM File="C:\Program Files\JardicPro\JardicPro.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="929792" Attr="rsAh" CreateDate="14.02.2009 5:06:44" ChageDate="14.02.2009 5:06:44" MD5="1F6ED50A6AE23C313B651CC2D4042363" X1="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\Jardic Pro.lnk" X3="" />
  <ITEM File="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\idsvc" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel.Install 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\yukonwxp.sys" CheckResult="-1" Enabled="1" Type="REG" Size="174464" Attr="rsAh" CreateDate="23.12.2003 5:32:00" ChageDate="23.12.2003 5:32:00" MD5="265B882E0501AC6D06F083B04AF488A8" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\yukonwxp" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\dot3svc.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dot3Svc" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\msshavmsg.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSHA" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\KB905474\wgasetup.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\ff_vfw.dll" CheckResult="-1" Enabled="1" Type="REG" Size="85504" Attr="rsAh" CreateDate="09.04.2009 13:33:16" ChageDate="13.10.2009 23:00:00" MD5="B3F4C12D9728FF44244DB30D41E58062" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Drivers32" X3="VIDC.FFDS" />
  <ITEM File="C:\WINDOWS\system32\ir32_32.dll" CheckResult="-1" Enabled="1" Type="REG" Size="202240" Attr="rsAh" CreateDate="20.10.2001 17:00:00" ChageDate="26.06.2000 10:57:16" MD5="379204E614B66D00B414229051D0C9A4" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Drivers32" X3="vidc.iv31" />
  <ITEM File="C:\WINDOWS\system32\ir32_32.dll" CheckResult="-1" Enabled="1" Type="REG" Size="202240" Attr="rsAh" CreateDate="20.10.2001 17:00:00" ChageDate="26.06.2000 10:57:16" MD5="379204E614B66D00B414229051D0C9A4" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Drivers32" X3="vidc.iv32" />
  <ITEM File="C:\WINDOWS\system32\iyvu9_32.dll" CheckResult="-1" Enabled="1" Type="REG" Size="56320" Attr="rsah" CreateDate="11.08.2009 18:39:06" ChageDate="22.06.2000 12:09:24" MD5="94A8EBD816A366041F8CCF5AFD3AB7DE" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Drivers32" X3="vidc.yvu9" />
  <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime Optimization Service" X3="EventMessageFile" />
  <ITEM File="F:\проги\Download Master\dmaster.exe" CheckResult="-1" Enabled="1" Type="REG" Size="3778048" Attr="rsAh" CreateDate="29.08.2009 19:57:25" ChageDate="07.11.2009 0:50:36" MD5="B7A938C07891D3FAA2BDCB989BFCBD13" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Download Master" />
  <ITEM File="F:\проги\Download Master\dmaster.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="3778048" Attr="rsAh" CreateDate="29.08.2009 19:57:25" ChageDate="07.11.2009 0:50:36" MD5="B7A938C07891D3FAA2BDCB989BFCBD13" NationalName="Y" X1="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\FallenAngel\Application Data\Microsoft\Internet Explorer\Quick Launch\Download Master.lnk" X3="" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0\Performance" X3="Library" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0\Performance" X3="Library" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0\Performance" X3="Library" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0\Performance" X3="Library" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0\Performance" X3="Library" />
  <ITEM File="NETFXPerf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0\Performance" X3="Library" />
  <ITEM File="SDEvents.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search @amp; Destroy 2" X3="EventMessageFile" />
  <ITEM File="W:\usr\local\mysql\bin\mysqld-nt.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\MySQL" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMI.NET Provider Extension" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui;c:\WINDOWS\system32\icardres.dll.mui" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0" X3="EventMessageFile" />
  <ITEM File="dot3gpclnt.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}" X3="DLLName" />
  <ITEM File="kbd101a.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\i8042prt\Parameters" X3="LayerDriver KOR" />
  <ITEM File="mscoree.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NETFramework\Performance" X3="Library" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2=".DEFAULT\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-19\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-20\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-18\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_CURRENT_USER" X2="Control Panel\IOProcs" X3="MVB" />
  <ITEM File="netfxperf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NET CLR Data\Performance" X3="Library" />
  <ITEM File="netfxperf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance" X3="Library" />
  <ITEM File="netfxperf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle\Performance" X3="Library" />
  <ITEM File="netfxperf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer\Performance" X3="Library" />
  <ITEM File="vgafix.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fixedfon.fon" />
  <ITEM File="vgaoem.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="oemfonts.fon" />
  <ITEM File="vgasys.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fonts.fon" />
 </AUTORUN>
 <BHO>
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{dfbeb35b-444d-4f25-8d7d-eb2683c206ec}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{dfbeb35b-444d-4f25-8d7d-eb2683c206ec}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{32099AAC-C132-4136-9E9A-4E364A424E17}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" CLSID="{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}" Descr="" LegalCopyright=""   />
  <ITEM File="F:\проги\Download Master\dmaster.exe" CheckResult="-1" Enabled="1" BHOType="3" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" CLSID="{8DAE90AD-4583-4977-9DD4-4360F7A45C74}" Descr="Download Master" LegalCopyright="2002-2009 WestByte" Size="3778048" Attr="rsAh" CreateDate="29.08.2009 19:57:25" ChageDate="07.11.2009 0:50:36" MD5="B7A938C07891D3FAA2BDCB989BFCBD13" NationalName="Y"  />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="4" RegKey="HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks" CLSID="{83821C2B-32A8-4DD7-B6D4-44309A78E668}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="4" RegKey="HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks" CLSID="{dfbeb35b-444d-4f25-8d7d-eb2683c206ec}" Descr="" LegalCopyright=""   />
 </BHO>
 <ExplorerExt>
  <ITEM File="deskpan.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Расширение CPL панорамирования дисплея" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071714-76d4-11d1-8b24-00a0c9068ff3}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Панель задач и меню @apos;@apos;Пуск@apos;@apos;" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0DF44EAA-FF21-4412-828E-260A8728E7F1}" Descr="" LegalCopyright=""   />
  <ITEM File="rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Autoplay for SlideShow" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Учетные записи пользователей" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7A9D77BD-5403-11d2-8785-2E0420524153}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="ShellLink for Application References" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{e82a2d71-5b2f-43a0-97b8-81be15854de8}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Shell Icon Handler for Application References" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Fusion Cache" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1D2680C9-0E2A-469d-B787-065558BC7D43}" Descr="" LegalCopyright=""   />
 </ExplorerExt>
 <PrintEXT>
 </PrintEXT>
 <TaskScheduler>
 </TaskScheduler>
 <SPI>
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="TCP/IP" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\System32\winrnr.dll" CheckResult="-1" SPIType="1" SPINaim="NTDS" Descr="LDAP RnR Provider DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="16896" Attr="rsAh" CreateDate="17.08.2004 17:04:36" ChageDate="17.08.2004 17:04:36" MD5="852E8D4F6B83CAF662D199E79D5557EA"  />
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="Пространство имен службы сетевого расположения (NLA)" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\wshbth.dll" CheckResult="-1" SPIType="1" SPINaim="Пространство имен Bluetooth" Descr="Windows Sockets Helper DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="108032" Attr="rsAh" CreateDate="17.08.2004 17:04:36" ChageDate="17.08.2004 15:04:36" MD5="4701970CD9E693D25104D8E442C53D10"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Irda [IrDA]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [TCP/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [UDP/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [RAW/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP UDP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="20.10.2001 17:00:00" ChageDate="20.10.2001 17:00:00" MD5="07078A8814E6DD87C27BB0D8A2163D23"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP TCP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="20.10.2001 17:00:00" ChageDate="20.10.2001 17:00:00" MD5="07078A8814E6DD87C27BB0D8A2163D23"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD RfComm [Bluetooth]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{559299C6-79A8-48D2-A151-D1EC33E56AC0}] SEQPACKET 8" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{559299C6-79A8-48D2-A151-D1EC33E56AC0}] DATAGRAM 8" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{0D52CB84-5DC7-4935-A49B-DEA536338B17}] SEQPACKET 7" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{0D52CB84-5DC7-4935-A49B-DEA536338B17}] DATAGRAM 7" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F45E773C-C359-4F7D-A2D8-39DC28073F43}] SEQPACKET 5" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F45E773C-C359-4F7D-A2D8-39DC28073F43}] DATAGRAM 5" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D9C601BA-8281-40E8-A591-E82EF4D45EAF}] SEQPACKET 0" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D9C601BA-8281-40E8-A591-E82EF4D45EAF}] DATAGRAM 0" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{2C6AC010-7891-4B6A-8887-C8B57A908704}] SEQPACKET 6" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{2C6AC010-7891-4B6A-8887-C8B57A908704}] DATAGRAM 6" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{1E6B0B1C-658E-440A-BDC1-6B8CEEEE0353}] SEQPACKET 1" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{1E6B0B1C-658E-440A-BDC1-6B8CEEEE0353}] DATAGRAM 1" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D33BA183-0692-46BC-A69A-590134D58EEC}] SEQPACKET 2" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D33BA183-0692-46BC-A69A-590134D58EEC}] DATAGRAM 2" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{8A38517D-2CE5-4725-92ED-45BE885C6EFA}] SEQPACKET 3" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{8A38517D-2CE5-4725-92ED-45BE885C6EFA}] DATAGRAM 3" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{6FB5EDF2-9B8E-4DFD-A7F4-3107A0D6DFF1}] SEQPACKET 4" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{6FB5EDF2-9B8E-4DFD-A7F4-3107A0D6DFF1}] DATAGRAM 4" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="17.08.2004 17:04:26" ChageDate="20.06.2008 22:42:17" MD5="1E95CA5E35D7D633D51BAB16436C21F4"  />
 </SPI>
 <DPF>
 </DPF>
 <CPL>
 </CPL>
 <ActiveSetup>
 </ActiveSetup>
 <HOSTS>
  <ITEM Line="	127.0.0.1		localhost" />
  <ITEM Line="127.0.0.1 mpa.one.microsoft.com" />
 </HOSTS>
 <SuspFiles>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys" VirType="4" Descr="Перехватчик KernelMode"  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\FStarForce.sys" VirType="4" Descr="Перехватчик KernelMode"  />
 </SuspFiles>
 <RK_KM>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtAdjustPrivilegesToken" FIndx="11" HookPtr="A9006A72" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtClose" FIndx="25" HookPtr="A900701E" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtConnectPort" FIndx="31" HookPtr="A9008A82" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtCreateFile" FIndx="37" HookPtr="A9008438" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtCreateKey" FIndx="41" HookPtr="A90061E8" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtCreateSymbolicLinkObject" FIndx="52" HookPtr="A900A3E4" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtCreateThread" FIndx="53" HookPtr="A9006E1A" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtDeleteKey" FIndx="63" HookPtr="A900662A" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtDeleteValueKey" FIndx="65" HookPtr="A900682A" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtDeviceIoControlFile" FIndx="66" HookPtr="A9008744" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtDuplicateObject" FIndx="68" HookPtr="A900A8F0" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtEnumerateKey" FIndx="71" HookPtr="A9006940" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtEnumerateValueKey" FIndx="73" HookPtr="A90069A8" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtFsControlFile" FIndx="84" HookPtr="A90085FA" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtLoadDriver" FIndx="97" HookPtr="A9009EA8" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtOpenFile" FIndx="116" HookPtr="A9008294" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtOpenKey" FIndx="119" HookPtr="A900634A" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtOpenProcess" FIndx="122" HookPtr="A9006C40" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtOpenSection" FIndx="125" HookPtr="A900A40E" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtOpenThread" FIndx="128" HookPtr="A9006B96" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtQueryKey" FIndx="160" HookPtr="A9006A10" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtQueryMultipleValueKey" FIndx="161" HookPtr="A9006714" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtQueryValueKey" FIndx="177" HookPtr="A90064F2" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtQueueApcThread" FIndx="180" HookPtr="A900A110" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtReplaceKey" FIndx="193" HookPtr="A9005E6A" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtRequestWaitReplyPort" FIndx="200" HookPtr="A900930C" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtRestoreKey" FIndx="204" HookPtr="A9005FCC" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtResumeThread" FIndx="206" HookPtr="A900A7C0" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSaveKey" FIndx="207" HookPtr="A9005C68" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSecureConnectPort" FIndx="210" HookPtr="A9008924" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSetContextThread" FIndx="213" HookPtr="A9006F18" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSetSecurityObject" FIndx="237" HookPtr="A9009FA2" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSetSystemInformation" FIndx="240" HookPtr="A900A438" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSetValueKey" FIndx="247" HookPtr="A90063A0" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSuspendProcess" FIndx="253" HookPtr="A900A51C" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSuspendThread" FIndx="254" HookPtr="A900A648" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtSystemDebugControl" FIndx="255" HookPtr="A9009DD4" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtTerminateProcess" FIndx="257" HookPtr="A9006CEA" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="C:\WINDOWS\system32\DRIVERS\klif.sys"  FNaim="NtWriteVirtualMemory" FIndx="277" HookPtr="A9006D5C" HookType="1" CheckResult="0" Size="213520" Attr="rsAh" CreateDate="18.02.2009 14:55:49" ChageDate="06.11.2009 18:33:23" MD5="058920ABBB6B531D3AE72403990367B6"/>
  <ITEM File="\SystemRoot\system32\DRIVERS\klif.sys"  FNaim="NtQueryPerformanceCounter" FIndx="165" HookPtr="80634F75" HookType="3" />
  <ITEM File=""  FNaim="" FIndx="292" HookPtr="80634F75" HookType="3" />
  <ITEM File="\SystemRoot\system32\DRIVERS\klif.sys"  FNaim="" FIndx="387" HookPtr="80634F75" HookType="3" />
  <ITEM File="\SystemRoot\system32\DRIVERS\FStarForce.sys"  FNaim="" FIndx="550" HookPtr="80634F75" HookType="3" />
 </RK_KM>
 <RK_IRP>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="0" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="2" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="4" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="5" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="6" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="7" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="8" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="10" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="11" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="12" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="13" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="14" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="17" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="20" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="21" HookPtr="8A5221F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="27" HookPtr="8A5221F8"/>
 </RK_IRP>
 <WIZARD-TSW>
  <ITEM ID="58" Level="3" Fixed="0" />
  <ITEM ID="59" Level="3" Fixed="0" />
  <ITEM ID="61" Level="2" Fixed="0" />
 </WIZARD-TSW>
</AVZ>
