<?xml version="1.0" encoding="windows-1251" ?>
<!-- AVZ XML Report -->
<AVZ Version="4.32" LogDate="30.06.2010 19:04:51" WinDir="C:\WINDOWS\" ProfileDir="C:\Documents and Settings\Ludmila" IsWow64="False" CompHash="4F5261DD7E8AB6BB45512DC2E551E318">
 <PROCESS>
  <ITEM PID="1900" File="c:\program files\aura\aura.exe" CheckResult="-1" Descr="Nature ambient sounds shell" LegalCopyright="© Alexander Glazkov, 2003-2006" Hidden="0"  CmdLine="@quot;C:\Program Files\Aura\aura.exe@quot; gstart" Size="330171" Attr="rsAh" CreateDate="06.02.2007 18:01:43" ChageDate="06.02.2007 18:01:43" MD5="37D8C72D2B93C98FB0DDBF763C86311F" />
  <ITEM PID="2340" File="c:\program files\mozilla firefox\firefox.exe" CheckResult="0" Descr="Firefox" LegalCopyright="©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable." Hidden="0"  CmdLine="@quot;C:\Program Files\Mozilla Firefox\firefox.exe@quot; " Size="307672" Attr="rsAh" CreateDate="18.01.2007 23:11:19" ChageDate="18.12.2009 14:17:44" MD5="231FAD335D7D33BCA09549784B7F9657" />
  <ITEM PID="1384" File="c:\documents and settings\ludmila\application data\qipguard\qipguard.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="@quot;C:\Documents and Settings\Ludmila\Application Data\QipGuard\QipGuard.exe@quot; " Size="190416" Attr="rsAh" CreateDate="30.06.2010 17:03:40" ChageDate="10.06.2010 15:07:50" MD5="E058C34567C4BF05CA40D3FB52A5A00A" />
  <ITEM PID="868" File="c:\windows\system32\winlogon.exe" CheckResult="0" Descr="Windows NT Logon Application" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="winlogon.exe" Size="502272" Attr="rsAh" CreateDate="04.08.2004 1:56:58" ChageDate="04.08.2004 1:56:58" MD5="01C3346C241652F43AED8E2149881BFE" />
 </PROCESS>
 <DLL>
  <ITEM File="C:\Documents and Settings\Ludmila\Application Data\Mozilla\Firefox\Profiles\5x3waul2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2340" Hidden="0" Size="43008" Attr="rsAh" CreateDate="29.06.2010 19:06:15" ChageDate="17.06.2010 14:35:34" MD5="638121F6FEB6E7EC87AC5A6D10C24501" />
  <ITEM File="C:\Documents and Settings\Ludmila\Application Data\Mozilla\Firefox\Profiles\5x3waul2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2340" Hidden="0" Size="346112" Attr="rsAh" CreateDate="29.06.2010 19:06:15" ChageDate="17.06.2010 14:35:12" MD5="7C7B243EF2394A30EF31A10A327124C8" />
  <ITEM File="C:\Documents and Settings\Ludmila\Application Data\Mozilla\Firefox\Profiles\5x3waul2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2340" Hidden="0" Size="1496064" Attr="rsAh" CreateDate="29.06.2010 19:06:15" ChageDate="17.06.2010 14:35:52" MD5="0CAC6B90D2FC892417B0F31DE77DCF5D" />
  <ITEM File="C:\WINDOWS\SYSTEM32\WgaLogon.dll" CheckResult="-1"  Descr="Windows Genuine Advantage Notification"  LegalCopyright="© 1995-2006 Microsoft Corporation"  UsedBy="868" Hidden="0" Size="3584" Attr="rsah" CreateDate="18.01.2007 23:38:00" ChageDate="27.06.2006 7:40:00" MD5="25C443F17024BF5BB0277301B22CB1D4" />
 </DLL>
 <KERNELOBJ>
  <ITEM File="C:\WINDOWS\System32\Drivers\afm9aejb.SYS" CheckResult="-1" Base="F67ED000" MemSize="04A000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="F3A5B000" MemSize="018000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS" CheckResult="-1" Base="F7B51000" MemSize="002000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys" CheckResult="-1" Base="F7443000" MemSize="0D7000" Descr="" LegalCopyright="" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5="" />
 </KERNELOBJ>
 <Service>
  <ITEM File="%fystemRoot%\system32\svchost.exe" Name="BITS" CheckResult="-1" Type="32" State="1"   />
  <ITEM File="D:\Program Files\Novosoft\Handy Backup\BackupNetworkCoordinator.exe" Name="NovosoftBackupNetworkCoordinator" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="D:\Program Files\Serv-U\ServUDaemon.exe" Name="Serv-U" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="%fystemroot%\system32\svchost.exe" Name="wuauserv" CheckResult="-1" Type="32" State="1"   />
  <ITEM File="hex(2):25" Name="WudfSvc" CheckResult="-1" Type="32" State="1"   />
 </Service>
 <Drivers>
  <ITEM File="C:\WINDOWS\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""  />
  <ITEM File="Abiosdsk.sys" Name="Abiosdsk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="abp480n5.sys" Name="abp480n5" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="adpu160m.sys" Name="adpu160m" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Aha154x.sys" Name="Aha154x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78u2.sys" Name="aic78u2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78xx.sys" Name="aic78xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="AliIde.sys" Name="AliIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="amsint.sys" Name="amsint" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc.sys" Name="asc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3350p.sys" Name="asc3350p" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3550.sys" Name="asc3550" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Atdisk.sys" Name="Atdisk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="cd20xrnt.sys" Name="cd20xrnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Changer.sys" Name="Changer" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="CmdIde.sys" Name="CmdIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Cpqarray.sys" Name="Cpqarray" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dac960nt.sys" Name="dac960nt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dpti2o.sys" Name="dpti2o" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="hpn.sys" Name="hpn" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omgmt.sys" Name="i2omgmt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omp.sys" Name="i2omp" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ini910u.sys" Name="ini910u" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="IntelIde.sys" Name="IntelIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="lbrtfdc.sys" Name="lbrtfdc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="mraid35x.sys" Name="mraid35x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PCIDump.sys" Name="PCIDump" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDCOMP.sys" Name="PDCOMP" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDFRAME.sys" Name="PDFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRELI.sys" Name="PDRELI" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRFRAME.sys" Name="PDRFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2.sys" Name="perc2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2hib.sys" Name="perc2hib" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1080.sys" Name="ql1080" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Ql10wnt.sys" Name="Ql10wnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql12160.sys" Name="ql12160" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1240.sys" Name="ql1240" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1280.sys" Name="ql1280" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Simbad.sys" Name="Simbad" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Sparrow.sys" Name="Sparrow" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\Drivers\SSPORT.sys" Name="SSPORT" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="sym_hi.sys" Name="sym_hi" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="sym_u3.sys" Name="sym_u3" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc810.sys" Name="symc810" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc8xx.sys" Name="symc8xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="TosIde.sys" Name="TosIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ultra.sys" Name="ultra" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ViaIde.sys" Name="ViaIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="WDICA.sys" Name="WDICA" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="hex(2):73" Name="WudfPf" CheckResult="-1" Type="1" State="1"   />
 </Drivers>
 <AUTORUN>
  <ITEM File="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\InterLAN (2).lnk" CheckResult="-1" Enabled="1" Type="FILE" Size="568" Attr="rsAh" CreateDate="09.03.2009 10:39:42" ChageDate="09.03.2009 10:39:42" MD5="D96B84B45145C830FA6B9E85C47078DC" X1="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\InterLAN (2).lnk" X3="" />
  <ITEM File="C:\Documents and Settings\Ludmila\Application Data\QipGuard\QipGuard.exe" CheckResult="-1" Enabled="1" Type="REG" Size="190416" Attr="rsAh" CreateDate="30.06.2010 17:03:40" ChageDate="10.06.2010 15:07:50" MD5="E058C34567C4BF05CA40D3FB52A5A00A" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="QIP Internet Guardian" />
  <ITEM File="C:\Documents and Settings\Ludmila\Desktop\Рисунки 2. Ответственность за правонарушения ppt.ppt" CheckResult="-1" Enabled="1" Type="LNK" Size="12017152" Attr="rsAh" CreateDate="30.03.2008 19:32:40" ChageDate="26.06.2009 20:08:53" MD5="FF5782F95BCCA889DB3A685D7EC45A26" NationalName="Y" X1="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\Рисунки 2. Ответственность за правонарушения ppt.ppt.lnk" X3="" />
  <ITEM File="C:\Program Files\Aura\aura.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="330171" Attr="rsAh" CreateDate="06.02.2007 18:01:43" ChageDate="06.02.2007 18:01:43" MD5="37D8C72D2B93C98FB0DDBF763C86311F" X1="C:\Documents and Settings\Ludmila\Start Menu\Programs\Startup\" X2="C:\Documents and Settings\Ludmila\Start Menu\Programs\Startup\Aura.lnk" X3="" />
  <ITEM File="C:\Program Files\QIP Infium\infium.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="5809616" Attr="rsAh" CreateDate="11.11.2008 21:46:12" ChageDate="10.06.2010 15:07:54" MD5="6B69A7ABA6E1F4B80E528911B6ACB123" X1="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\QIP Infium.lnk" X3="" />
  <ITEM File="C:\WINDOWS\Installer\{8DC42D05-680B-41B0-8878-6C14D24602DB}\QTPlayer.ico" CheckResult="-1" Enabled="1" Type="LNK" Size="22486" Attr="RsAh" CreateDate="09.11.2008 17:53:28" ChageDate="09.11.2008 17:53:28" MD5="BE32B7F123578321A616C42C2BF2432D" X1="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Ludmila\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime-плеер.lnk" X3="" />
  <ITEM File="C:\WINDOWS\System32\igmpv2.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ipbootp.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\iprip2.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ospf.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ospfmib.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\polagent.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\tssdis.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\MsSip1.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\MsSip2.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\MsSip3.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" Type="REG" Size="270848" Attr="rsAh" CreateDate="23.09.2005 8:28:52" ChageDate="23.09.2005 8:28:52" MD5="0A1E1F92EEAF919D031D08E4A8449CA4" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" Type="REG" Size="270848" Attr="rsAh" CreateDate="23.09.2005 8:28:52" ChageDate="23.09.2005 8:28:52" MD5="0A1E1F92EEAF919D031D08E4A8449CA4" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime Optimization Service" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\pavcpl.cpl" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls" X3="PavCPL" />
  <ITEM File="C:\WINDOWS\system32\psxss.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="System\CurrentControlSet\Control\Session Manager\SubSystems" X3="Posix" />
  <ITEM File="C:\WINDOWS\system32\stisvc.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System" X3="EventMessageFile" />
  <ITEM File="D:\Program Files\Novosoft\Handy Backup\HBPlugins\esebcli2.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESE BACKUP" X3="EventMessageFile" />
  <ITEM File="D:\Program Files\Serv-U\ServUDaemon.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Serv-U FTP Server" X3="EventMessageFile" />
  <ITEM File="WgaLogon.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon" X3="DLLName" />
  <ITEM File="d:\Program Files\Serv-U\ServUPerfCount.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Serv-U-Counters\Performance" X3="Library" />
  <ITEM File="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WudfSvc\Parameters" X3="ServiceDll" />
  <ITEM File="mscoree.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\.NETFramework\Performance" X3="Library" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2=".DEFAULT\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-19\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-20\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-18\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_CURRENT_USER" X2="Control Panel\IOProcs" X3="MVB" />
  <ITEM File="vgafix.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fixedfon.fon" />
  <ITEM File="vgaoem.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="oemfonts.fon" />
  <ITEM File="vgasys.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fonts.fon" />
 </AUTORUN>
 <BHO>
  <ITEM File="C:\Program Files\ICQ6\ICQ.exe" CheckResult="-1" Enabled="1" BHOType="3" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" CLSID="{E59EB121-F339-4851-A3BA-FE49C35617C2}" Descr="ICQ" LegalCopyright="Copyright (c) 1998-2005 America Online, Inc." Size="176128" Attr="rsAh" CreateDate="18.01.2007 14:36:46" ChageDate="18.01.2007 14:36:27" MD5="DD184CA3E1EE7603FDE0FD58FF3CFA2C"  />
 </BHO>
 <ExplorerExt>
  <ITEM File="deskpan.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Display Panning CPL Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071714-76d4-11d1-8b24-00a0c9068ff3}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Shell extensions for file compression" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{764BF0E1-F219-11ce-972D-00AA00A14F56}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Encryption Context Menu" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Briefcase" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{85BBD920-42A0-1069-A2E4-08002B30309D}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Taskbar and Start Menu" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0DF44EAA-FF21-4412-828E-260A8728E7F1}" Descr="" LegalCopyright=""   />
  <ITEM File="rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Autoplay for SlideShow" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="User Accounts" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7A9D77BD-5403-11d2-8785-2E0420524153}" Descr="" LegalCopyright=""   />
  <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Fusion Cache" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1D2680C9-0E2A-469d-B787-065558BC7D43}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation.  All rights reserved." Size="270848" Attr="rsAh" CreateDate="23.09.2005 8:28:52" ChageDate="23.09.2005 8:28:52" MD5="0A1E1F92EEAF919D031D08E4A8449CA4"  />
 </ExplorerExt>
 <PrintEXT>
 </PrintEXT>
 <TaskScheduler>
 </TaskScheduler>
 <SPI>
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="Tcpip" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\System32\winrnr.dll" CheckResult="-1" SPIType="1" SPINaim="NTDS" Descr="LDAP RnR Provider DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="16896" Attr="rsAh" CreateDate="04.08.2004 1:56:48" ChageDate="04.08.2004 1:56:48" MD5="2C8FDB176F22629EA5342DB474FAC391"  />
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="Network Location Awareness (NLA) Namespace" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\Program Files\Bonjour\mdnsNSP.dll" CheckResult="-1" SPIType="1" SPINaim="mdnsNSP" Descr="Bonjour Namespace Provider" LegalCopyright="Copyright (C) 2003-2008 Apple Inc." Size="147456" Attr="rsAh" CreateDate="29.08.2008 10:53:50" ChageDate="29.08.2008 10:53:50" MD5="0E3E56064E162EE9CC48698355098301"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32 protected [MSAFD Tcpip [TCP/IP]]" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32 protected [MSAFD Tcpip [UDP/IP]]" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32 protected [MSAFD Tcpip [RAW/IP]]" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32 protected [RSVP UDP Service Provider]" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32 protected [RSVP TCP Service Provider]" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [TCP/IP]" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [UDP/IP]" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [RAW/IP]" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP UDP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="23.08.2001 16:00:00" ChageDate="23.08.2001 16:00:00" MD5="90491683ABD587C702B16F181AB0D99D"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP TCP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="23.08.2001 16:00:00" ChageDate="23.08.2001 16:00:00" MD5="90491683ABD587C702B16F181AB0D99D"  />
  <ITEM File="C:\WINDOWS\system32\imon.dll" CheckResult="-1" SPIType="3" SPINaim="NOD32" Descr="NOD32 IMON - Internet scanning support" LegalCopyright="Copyright (c) 1992-2005 Eset " Size="270336" Attr="rsAh" CreateDate="20.01.2007 0:17:44" ChageDate="20.01.2007 0:17:27" MD5="7E726F244D0BD744E1CAD96C6BD9B447"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D863CBEC-2F2B-4257-B06F-E6DED68B8794}] SEQPACKET 7" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D863CBEC-2F2B-4257-B06F-E6DED68B8794}] DATAGRAM 7" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{6F52F815-9AB5-4A8A-A0F8-6918EE55E532}] SEQPACKET 6" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{6F52F815-9AB5-4A8A-A0F8-6918EE55E532}] DATAGRAM 6" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{8769E6B5-88B1-41A4-A65F-DF6E2703F7F3}] SEQPACKET 0" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{8769E6B5-88B1-41A4-A65F-DF6E2703F7F3}] DATAGRAM 0" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{344A6176-5330-465D-8DC8-24A992123647}] SEQPACKET 5" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{344A6176-5330-465D-8DC8-24A992123647}] DATAGRAM 5" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{3D38FB80-47CB-4ED1-8E95-D42ED970352D}] SEQPACKET 1" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{3D38FB80-47CB-4ED1-8E95-D42ED970352D}] DATAGRAM 1" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F41C839A-72D8-495C-B471-917BAF44071C}] SEQPACKET 2" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F41C839A-72D8-495C-B471-917BAF44071C}] DATAGRAM 2" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{04442877-1AD3-4BCC-8025-2BE70B25848F}] SEQPACKET 3" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{04442877-1AD3-4BCC-8025-2BE70B25848F}] DATAGRAM 3" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{3FDF29A5-FE4C-459F-968A-CE109F7158EC}] SEQPACKET 4" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{3FDF29A5-FE4C-459F-968A-CE109F7158EC}] DATAGRAM 4" Descr="Microsoft Windows Sockets 2.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="245248" Attr="rsAh" CreateDate="04.08.2004 1:56:46" ChageDate="04.08.2004 1:56:46" MD5="4E74AF063C3271FBEA20DD940CFD1184"  />
 </SPI>
 <DPF>
 </DPF>
 <CPL>
 </CPL>
 <ActiveSetup>
 </ActiveSetup>
 <HOSTS>
  <ITEM Line="127.0.0.1       localhost" />
  <ITEM Line="216.55.133.9	handybackup.com www.handybackup.com www.softlogica.com softlogica.com" />
 </HOSTS>
 <SuspFiles>
  <ITEM File="C:\WINDOWS\cmstp.exe" VirType="3" Descr=" ЭПС: подозрение на Файл с подозрительным именем (CH) (высокая степень вероятности)"  />
 </SuspFiles>
 <RK_KM>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtCreateKey" FIndx="41" HookPtr="F74440B0" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtEnumerateKey" FIndx="71" HookPtr="F744984E" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtEnumerateValueKey" FIndx="73" HookPtr="F7449BEE" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtOpenKey" FIndx="119" HookPtr="F7444090" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtQueryKey" FIndx="160" HookPtr="F7449CC6" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtQueryValueKey" FIndx="177" HookPtr="F7449B46" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
  <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys"  FNaim="NtSetValueKey" FIndx="247" HookPtr="F7449D58" HookType="1" CheckResult="-1" Size="639224" Attr="rsAh" CreateDate="19.01.2007 2:50:12" ChageDate="19.01.2007 2:50:12" MD5=""/>
 </RK_KM>
 <RK_IRP>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="0" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="2" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="4" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="5" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="6" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="7" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="8" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="10" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="11" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="12" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="13" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="14" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="17" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="20" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="21" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="27" HookPtr="86D5F1D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="0" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="2" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="4" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="5" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="6" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="7" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="8" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="10" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="11" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="12" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="13" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="14" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="17" HookPtr="866A71D8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="27" HookPtr="866A71D8"/>
 </RK_IRP>
 <WIZARD-TSW>
  <ITEM ID="32" Level="3" Fixed="0" />
  <ITEM ID="58" Level="3" Fixed="0" />
  <ITEM ID="59" Level="3" Fixed="0" />
  <ITEM ID="61" Level="2" Fixed="0" />
 </WIZARD-TSW>
</AVZ>
