<?xml version="1.0" encoding="windows-1251" ?>
<!-- AVZ XML Report -->
<AVZ Version="4.35" LogDate="15.05.2011 20:51:15" WinDir="C:\WINDOWS\" OS_MjVer="5" OS_MiVer="1" OS_Build="2600" BootMode="0" OS_CSDV="Service Pack 2" ProfileDir="C:\Documents and Settings\Fenix" Session="Console" IsWow64="False" IsAdmin="True" IsSRDisabled="False" MainDBDate="25.08.2010" CompHash="D2CFB601DCE1AE23E165C290E8E506AC">
 <PROCESS>
  <ITEM PID="300" File="d:\zakachka\Качка\скачка\Для компа\avz4\avz4\avz.exe" CheckResult="0" Descr="Антивирусная утилита AVZ" LegalCopyright="Антивирусная утилита AVZ" Hidden="0"  CmdLine="@quot;D:\Zakachka\Качка\скачка\Для компа\avz4\avz4\avz.exe@quot; " Size="770560" Attr="rsAh" CreateDate="15.05.2011 13:45:58" ChageDate="25.08.2010 15:50:30" MD5="AAA54EF85BE2564BACC563FAE471D460" NationalName="Y" />
  <ITEM PID="2920" File="c:\program files\ashampoo\ashampoo burning studio 9\burningstudio9.exe" CheckResult="0" Descr="" LegalCopyright="" Hidden="0"  CmdLine="@quot;C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\burningstudio9.exe@quot; " Size="1459552" Attr="rsAh" CreateDate="04.01.2010 03:42:05" ChageDate="30.06.2009 10:55:04" MD5="C6C8F013D57089A23063A3E7E130043C" />
  <ITEM PID="3404" File="c:\program files\ashampoo\ashampoo burning studio 9\cancelautoplay.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="@quot;C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\CancelAutoplay.exe@quot;" Size="110592" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="26.06.2009 15:34:34" MD5="89962AB73579BA4A993047D5FCD80921" />
  <ITEM PID="1216" File="c:\windows\system32\cshelper.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="C:\WINDOWS\system32\CSHelper.exe" Size="266240" Attr="rsAh" CreateDate="06.12.2010 23:44:25" ChageDate="06.12.2010 23:44:25" MD5="AEFB8558199BD5212B268B09BFA1D71A" />
  <ITEM PID="2992" File="c:\program files\daphne\daphne.exe" CheckResult="-1" Descr="Daphne" LegalCopyright="Copyright (C) 2010 - Leandro H. Fernandez" Hidden="0"  CmdLine="@quot;C:\Program Files\Daphne\Daphne.exe@quot; " Size="813568" Attr="rsAh" CreateDate="28.08.2010 18:30:04" ChageDate="28.08.2010 18:30:04" MD5="B6FFC8F6077B5D6C0CE791451DB41C62" />
  <ITEM PID="3032" File="c:\program files\common files\doctor web\scanning engine\dwengine.exe" CheckResult="-1" Descr="Dr.Web (R) Scanning Engine" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Hidden="0"  CmdLine="@quot;C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe@quot;" Size="1667416" Attr="rsAh" CreateDate="01.03.2011 16:48:36" ChageDate="01.03.2011 16:48:36" MD5="1F40F2B44E88E4719BBB5F71D996C6AF" />
  <ITEM PID="708" File="c:\program files\common files\doctor web\scanning engine\dwengine.exe" CheckResult="-1" Descr="Dr.Web (R) Scanning Engine" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Hidden="0"  CmdLine="watcher 3032 296 dwe-spider-bd8-1cc1324b3227212-watch" Size="1667416" Attr="rsAh" CreateDate="01.03.2011 16:48:36" ChageDate="01.03.2011 16:48:36" MD5="1F40F2B44E88E4719BBB5F71D996C6AF" />
  <ITEM PID="864" File="c:\windows\explorer.exe" CheckResult="0" Descr="Проводник" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Hidden="0"  CmdLine="C:\WINDOWS\Explorer.EXE" Size="1032704" Attr="rsAh" CreateDate="23.12.2006 00:39:31" ChageDate="23.12.2006 00:39:31" MD5="0A50E39F8B9DB9CB96FDFFABD77C2A0D" />
  <ITEM PID="216" File="c:\progra~1\foxits~1\foxitr~1\foxitr~1.exe" CheckResult="0" Descr="Foxit Reader, Best Reader for Everyday Use!" LegalCopyright="Copyright (C) 2005-2008 Foxit Software Company " Hidden="0"  CmdLine="@quot;C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE@quot;  @quot;D:\Zakachka\Качка\Psyhology\Френсис Йейтс - Искусство Памяти.pdf@quot;" Size="6823168" Attr="rsAh" CreateDate="06.12.2009 23:14:53" ChageDate="06.12.2009 23:14:35" MD5="8BAA7CF3BB0B57883D34D365C41DB96F" />
  <ITEM PID="348" File="c:\program files\drweb\frwl_svc.exe" CheckResult="-1" Descr="Dr.Web Firewall ® for Windows service" LegalCopyright="© Doctor Web, Ltd., 1992-2010" Hidden="0"  CmdLine="@quot;C:\Program Files\DrWeb\frwl_svc.exe@quot;" Size="2267120" Attr="rsAh" CreateDate="08.05.2011 14:01:17" ChageDate="20.04.2011 15:25:06" MD5="A58C270D36E45910077B6E178323B440" />
  <ITEM PID="1608" File="c:\program files\internet explorer\iexplore.exe" CheckResult="0" Descr="Internet Explorer" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Internet Explorer\iexplore.exe@quot; " Size="638816" Attr="rsAh" CreateDate="04.11.2009 19:23:14" ChageDate="08.03.2009 15:09:26" MD5="B60DDDD2D63CE41CB8C487FCFBB6419E" />
  <ITEM PID="1932" File="c:\program files\internet explorer\iexplore.exe" CheckResult="0" Descr="Internet Explorer" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Internet Explorer\iexplore.exe@quot; SCODEF:1608 CREDAT:145409" Size="638816" Attr="rsAh" CreateDate="04.11.2009 19:23:14" ChageDate="08.03.2009 15:09:26" MD5="B60DDDD2D63CE41CB8C487FCFBB6419E" />
  <ITEM PID="3416" File="c:\program files\internet explorer\iexplore.exe" CheckResult="0" Descr="Internet Explorer" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Internet Explorer\iexplore.exe@quot; SCODEF:1608 CREDAT:145425" Size="638816" Attr="rsAh" CreateDate="04.11.2009 19:23:14" ChageDate="08.03.2009 15:09:26" MD5="B60DDDD2D63CE41CB8C487FCFBB6419E" />
  <ITEM PID="1452" File="c:\windows\system32\lsass.exe" CheckResult="0" Descr="LSA Shell (Export Version)" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\lsass.exe" Size="13312" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="1952DDC36E60C313CD6ACBD07D4548D6" />
  <ITEM PID="356" File="c:\program files\common files\microsoft shared\vs7debug\mdm.exe" CheckResult="0" Descr="Machine Debug Manager" LegalCopyright="© Microsoft Corporation.  All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE@quot;" Size="322120" Attr="rsAh" CreateDate="20.06.2003 00:25:00" ChageDate="20.06.2003 00:25:00" MD5="11F714F85530A2BD134074DC30E99FCA" />
  <ITEM PID="1168" File="c:\program files\bonjour\mdnsresponder.exe" CheckResult="-1" Descr="Bonjour Service" LegalCopyright="Copyright (C) 2003-2010 Apple Inc." Hidden="0"  CmdLine="@quot;C:\Program Files\Bonjour\mDNSResponder.exe@quot;" Size="345376" Attr="rsAh" CreateDate="07.10.2010 12:23:00" ChageDate="07.10.2010 12:23:00" MD5="F832F1505AD8B83474BD9A5B1B985E01" />
  <ITEM PID="804" File="c:\program files\symantec\norton antibot\agent\bin\nabagent.exe" CheckResult="0" Descr="Norton AntiBot application" LegalCopyright="Copyright © 2007 Symantec Corporation. All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe@quot; SymantecAntiBotAgent" Size="4909592" Attr="RsAh" CreateDate="12.11.2007 23:59:32" ChageDate="12.11.2007 23:59:32" MD5="7F597C378C9ABD2187046A8816A26FF1" />
  <ITEM PID="2108" File="c:\program files\symantec\norton antibot\agent\bin\nabwatcher.exe" CheckResult="0" Descr="SymantecAntiBotWatcher" LegalCopyright="Copyright © 2007 Symantec Corporation. All rights reserved." Hidden="0"  CmdLine="@quot;C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABWatcher.exe@quot;" Size="539160" Attr="RsAh" CreateDate="12.11.2007 23:59:36" ChageDate="12.11.2007 23:59:36" MD5="7BB76F561C863899348A522D4492B15A" />
  <ITEM PID="740" File="c:\windows\system32\nvsvc32.exe" CheckResult="-1" Descr="NVIDIA Driver Helper Service, Version 81.40" LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\nvsvc32.exe" Size="131138" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="E64C56655F0ED9E595007997B47544B9" />
  <ITEM PID="1440" File="c:\windows\system32\services.exe" CheckResult="0" Descr="Приложение служб и контроллеров" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Hidden="0"  CmdLine="C:\WINDOWS\system32\services.exe" Size="108544" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="394BE1D5B35B031A94AE51C6F05E3967" />
  <ITEM PID="828" File="c:\program files\drweb\spideragent.exe" CheckResult="-1" Descr="SpIDer Agent for Windows" LegalCopyright="Copyright © Doctor Web, Ltd., 1992-2011" Hidden="0"  CmdLine="@quot;C:\Program Files\DrWeb\spideragent.exe@quot; " Size="1473264" Attr="rsAh" CreateDate="16.03.2011 17:11:12" ChageDate="20.04.2011 15:33:01" MD5="5EF1D63BAF30654E0A8619A993CA1D7C" />
  <ITEM PID="152" File="c:\program files\drweb\spiderml.exe" CheckResult="-1" Descr="SpIDer Mail ® for Windows Workstation " LegalCopyright="Copyright © Doctor Web, Ltd., 1992-2010" Hidden="0"  CmdLine="@quot;C:\Program Files\DrWeb\spiderml.exe@quot; -autorun" Size="1572592" Attr="rsAh" CreateDate="16.03.2011 17:11:28" ChageDate="16.03.2011 17:11:28" MD5="23EB2DA12DCE9E5A3CA58BBA22A01072" />
  <ITEM PID="636" File="c:\windows\system32\spoolsv.exe" CheckResult="0" Descr="Spooler SubSystem App" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\spoolsv.exe" Size="57856" Attr="rsAh" CreateDate="23.12.2006 00:40:18" ChageDate="23.12.2006 00:40:18" MD5="AD3D9D191AEA7B5445FE1D82FFBB4788" />
  <ITEM PID="1188" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\svchost.exe -k imgsvc" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="1616" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\svchost -k DcomLaunch" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="1676" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\svchost -k rpcss" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="1832" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\System32\svchost.exe -k netsvcs" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="2004" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\svchost.exe -k NetworkService" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="376" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\svchost.exe -k LocalService" Size="14336" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="5DB0AE95BF08D5A63C167648F1314C07" />
  <ITEM PID="2128" File="c:\windows\system32\wdfmgr.exe" CheckResult="0" Descr="Windows User Mode Driver Manager" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\WINDOWS\system32\wdfmgr.exe" Size="38912" Attr="rsAh" CreateDate="28.01.2005 14:44:28" ChageDate="28.01.2005 14:44:28" MD5="AB0A7CA90D9E3D6A193905DC1715DED0" />
  <ITEM PID="1396" File="c:\windows\system32\winlogon.exe" CheckResult="0" Descr="Программа входа в систему Windows NT" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Hidden="0"  CmdLine="winlogon.exe" Size="503808" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="BA9DF5930B2582C31C0C8E52C94DDA48" />
 </PROCESS>
 <DLL>
  <ITEM File="C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll" CheckResult="-1"  Descr="TCP redirector for VKSaver"  LegalCopyright="Copyright (C) 2009-2011 AudioVkontakte.ru"  UsedBy="300,2920,3404,1216,2992,3032,708,864,216,1608,1932,3416,1452,356,1168,804,2108,740,1440,636,1188,1616,1676,1832,2004,376,2128,1396" Hidden="0" Size="59904" Attr="rsAh" CreateDate="12.04.2011 08:53:12" ChageDate="12.04.2011 08:53:12" MD5="81EC3155BE3E324A759AE81F2B904242" />
  <ITEM File="C:\Program Files\Daphne\DRKHooks.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="300,2920,2992,864,216,1608,1932" Hidden="0" Size="43008" Attr="rsAh" CreateDate="17.06.2010 02:32:18" ChageDate="17.06.2010 02:32:18" MD5="A782256B899F259BA0DD7DA0F18907A5" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\ash_spti.dll" CheckResult="-1"  Descr="ASPI Emulator"  LegalCopyright="Copyright 2008"  UsedBy="2920" Hidden="0" Size="173408" Attr="rsAh" CreateDate="04.01.2010 03:42:05" ChageDate="30.06.2009 10:55:06" MD5="DE396DB54F1122AD794B36DD3D04311D" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\brtcdau.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="4527456" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:10" MD5="4CF6BF80E2789A5B613EE648C0B5CC00" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\acdw.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="3175776" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:22" MD5="8CA748F1BD5E57E26C73521F618E394C" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\acdwVorbis.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="263520" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:20" MD5="6AF9E414D94012CE975C7918E978D2CA" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\acdwFLAC.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="132448" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:20" MD5="D3FFC915AD6AA4A3EE20D83C4356214A" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\acdwWMA.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="99680" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:16" MD5="FFD180A1112D6B516AD4D767D9F9459A" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\decmpa.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="218464" Attr="rsAh" CreateDate="04.01.2010 03:42:05" ChageDate="30.06.2009 10:55:14" MD5="7118A55BD7C0488C4197A02968503274" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\bswx.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="8455520" Attr="rsAh" CreateDate="04.01.2010 03:42:05" ChageDate="30.06.2009 10:55:28" MD5="F8AA4C33B384170F02ED822CB0F8AB10" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\ash_amf.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="210272" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:18" MD5="41C8344421286E64D99E3A03F4566EBD" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\adav.dll" CheckResult="-1"  Descr="Ashampoo DiscForge Anvil"  LegalCopyright="Copyright © 2005-2008 ashampoo Technology GmbH @amp; Co. KG"  UsedBy="2920" Hidden="0" Size="3024224" Attr="rsAh" CreateDate="04.01.2010 03:42:05" ChageDate="30.06.2009 10:55:24" MD5="4C3E743A86CC4AB134CDB4043872C98D" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\moviediscplugin.dll" CheckResult="-1"  Descr="Moviedisc Dynamic Link Library"  LegalCopyright="Copyright (C) 2007"  UsedBy="2920" Hidden="0" Size="2147680" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="30.06.2009 10:55:30" MD5="5F5A9D65D6A92135B122A147AE64FCD8" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\ash_ffmpeg.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="180224" Attr="rsAh" CreateDate="04.01.2010 03:42:07" ChageDate="26.06.2009 15:21:56" MD5="935DDB7A493075D27A5AC7BFB63B69C7" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\avcodec-51_ash.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="3851490" Attr="rsAh" CreateDate="04.01.2010 03:42:08" ChageDate="08.06.2009 18:11:58" MD5="28E83E9A53969D2A2FABF69916BC34C4" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\avutil-49_ash.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="34462" Attr="rsAh" CreateDate="04.01.2010 03:42:09" ChageDate="08.06.2009 18:11:58" MD5="92034AE295C70929C6BE0081063E8FC8" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\avformat-51_ash.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="509607" Attr="rsAh" CreateDate="04.01.2010 03:42:09" ChageDate="08.06.2009 18:11:58" MD5="DD5A21612E36099AA693BF0D50A3560D" />
  <ITEM File="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" CheckResult="-1"  Descr="PDF Shell Extension"  LegalCopyright="Copyright 2000-2010 Adobe Systems Incorporated and its licensors. All rights reserved."  UsedBy="2920,864" Hidden="0" Size="378264" Attr="rsAh" CreateDate="22.09.2010 19:12:42" ChageDate="22.09.2010 19:12:42" MD5="FF575E76DA89A3CEDE920BB71EE2F3C7" />
  <ITEM File="C:\Program Files\KMPlayer\haali\splitter.ax" CheckResult="-1"  Descr="Haali Media Splitter"  LegalCopyright="Copyright (C) 2004-2009 Mike Matsnev"  UsedBy="2920" Hidden="0" Size="549888" Attr="rsAh" CreateDate="09.05.2010 18:25:29" ChageDate="01.02.2009 13:32:12" MD5="46CB64F648B8B045C4BE0943243FB7D0" />
  <ITEM File="C:\Program Files\KMPlayer\haali\mkzlib.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="80384" Attr="rsAh" CreateDate="09.05.2010 18:25:31" ChageDate="01.02.2009 13:26:56" MD5="101C34671DB1289A13895647B6C8818A" />
  <ITEM File="C:\Program Files\KMPlayer\haali\mkx.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="150016" Attr="rsAh" CreateDate="09.05.2010 18:25:30" ChageDate="01.02.2009 13:31:28" MD5="AFB9491DBE264F1F8EFA5AD3F317DD39" />
  <ITEM File="C:\Program Files\DrWeb\drwsxtn.dll" CheckResult="-1"  Descr="Dr.Web ® Shell Extension"  LegalCopyright="© Doctor Web, Ltd., 1992-2011"  UsedBy="2920,864" Hidden="0" Size="88616" Attr="rsAh" CreateDate="16.03.2011 17:09:50" ChageDate="16.03.2011 17:09:50" MD5="429FCDDCE00EC4961655DD57B2EF3DFE" />
  <ITEM File="C:\Program Files\Daphne\DRKShell.dll" CheckResult="-1"  Descr="TODO: @lt;File description@gt;"  LegalCopyright="TODO: (c) @lt;Company name@gt;.  All rights reserved."  UsedBy="2920,864" Hidden="0" Size="49152" Attr="rsAh" CreateDate="14.12.2009 03:58:16" ChageDate="14.12.2009 03:58:16" MD5="1382033D4056BAE3FACDA19247BF277C" />
  <ITEM File="C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\d3d9_swiftshader.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2920" Hidden="0" Size="1323008" Attr="rsAh" CreateDate="04.01.2010 03:42:08" ChageDate="11.03.2009 16:49:06" MD5="29878878ABFDE970F6C9EF429F7DE90F" />
  <ITEM File="C:\WINDOWS\system32\CSInstru.dll" CheckResult="-1"  Descr="Copysafe content protection system"  LegalCopyright="Copyright (C) 2007"  UsedBy="1216" Hidden="0" Size="225280" Attr="rsAh" CreateDate="06.12.2010 23:44:25" ChageDate="06.12.2010 23:44:25" MD5="626D283FA9F763E7E1ED9EDCEED9E93C" />
  <ITEM File="C:\Program Files\Daphne\SpyAgent.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2992" Hidden="0" Size="173568" Attr="rsAh" CreateDate="28.08.2010 16:53:40" ChageDate="28.08.2010 16:53:40" MD5="C6BA9340481E75FA42657AB7F0A8D038" />
  <ITEM File="C:\Program Files\Daphne\LTR.dll" CheckResult="-1"  Descr="Daphne"  LegalCopyright="Copyright (C) 2010 - Leandro H. Fernandez"  UsedBy="2992" Hidden="0" Size="105472" Attr="rsAh" CreateDate="17.06.2010 02:32:20" ChageDate="17.06.2010 02:32:20" MD5="2EDFE1AF5F1D65630982B70CB05A7686" />
  <ITEM File="C:\Program Files\Bonjour\mdnsNSP.dll" CheckResult="-1"  Descr="Bonjour Namespace Provider"  LegalCopyright="Copyright (C) 2003-2010 Apple Inc."  UsedBy="2992,864,1608,1932,3416,804,636,1676,376" Hidden="0" Size="152864" Attr="rsAh" CreateDate="07.10.2010 12:23:00" ChageDate="07.10.2010 12:23:00" MD5="C69DBFA61FE3DEA653A9B83C3A2B052B" />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1"  Descr="Dr.Web Winsock Provider Hook"  LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011"  UsedBy="2992,864,1932,3416,1452,1168,804,152,1676,1832,2004,376" Hidden="0" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A" />
  <ITEM File="C:\Program Files\Common Files\Doctor Web\Scanning Engine\vrcpp.dll" CheckResult="-1"  Descr="VadeRetro Antispam @amp; AV Filter"  LegalCopyright="Copyright Goto Software 2009"  UsedBy="3032" Hidden="0" Size="3014784" Attr="rsAh" CreateDate="16.03.2011 17:12:00" ChageDate="15.05.2011 16:48:02" MD5="6D1D5FB80D23CEF5E2EF64FF35F862D2" />
  <ITEM File="C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwse-ips.dll" CheckResult="-1"  Descr="Dr.Web (R) mini-IPS plugin"  LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011"  UsedBy="3032" Hidden="0" Size="17752" Attr="rsAh" CreateDate="01.03.2011 16:49:12" ChageDate="01.03.2011 16:49:12" MD5="D0FA6320F7B2BCC1624B701D674785EA" />
  <ITEM File="C:\WINDOWS\system32\nvcpl.dll" CheckResult="-1"  Descr="NVIDIA Display Properties Extension"  LegalCopyright="(C) NVIDIA Corporation. All rights reserved."  UsedBy="864" Hidden="0" Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987" />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="864" Hidden="0" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C" />
  <ITEM File="C:\Program Files\Adobe\Reader 9.0\Reader\viewerps.dll" CheckResult="-1"  Descr="Acrobat Viewer ProxyStub Library"  LegalCopyright="Copyright 2007-2010 Adobe Systems Incorporated and its licensors. All rights reserved."  UsedBy="864" Hidden="0" Size="16832" Attr="rsAh" CreateDate="22.09.2010 22:12:20" ChageDate="22.09.2010 22:12:20" MD5="25A1646E1CF0BC8DC4BE812DF7F17BE9" />
  <ITEM File="C:\Program Files\uTorrentBar\tbuTo1.dll" CheckResult="-1"  Descr="Conduit Toolbar"  LegalCopyright="Copyright © Conduit Ltd. 2008."  UsedBy="1608,1932,3416" Hidden="0" Size="3911776" Attr="rsAh" CreateDate="13.01.2011 16:33:25" ChageDate="13.01.2011 16:33:39" MD5="D9A0CE26ADA5BD15B1B03A752DDF14A6" />
  <ITEM File="C:\Documents and Settings\Fenix\Local Settings\Application Data\digitalchocolate\tbdigi.dll" CheckResult="-1"  Descr="Conduit Toolbar"  LegalCopyright="Copyright © Conduit Ltd. 2008."  UsedBy="1608,1932,3416" Hidden="0" Size="4162344" Attr="rsAh" CreateDate="05.03.2011 00:47:17" ChageDate="03.01.2011 11:13:54" MD5="D6A51F524DC545A55F107B5A5A502CC1" />
  <ITEM File="C:\Program Files\digitalchocolate\prxtbdigi.dll" CheckResult="-1"  Descr="Conduit Toolbar"  LegalCopyright="Copyright © Conduit Ltd. 2008."  UsedBy="1932,3416" Hidden="0" Size="175400" Attr="rsAh" CreateDate="13.01.2011 16:47:15" ChageDate="03.01.2011 11:16:50" MD5="3A5627E0AB06F3CA7FB238CE5EE8CDF9" />
  <ITEM File="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" CheckResult="-1"  Descr="Adobe PDF Helper for Internet Explorer"  LegalCopyright="Copyright 1984-2010 Adobe Systems Incorporated and its licensors. All rights reserved."  UsedBy="1932,3416" Hidden="0" Size="61888" Attr="rsAh" CreateDate="22.09.2010 19:04:20" ChageDate="22.09.2010 19:04:20" MD5="C3104BE7D2B689EBE47E2AAC64C07530" />
  <ITEM File="C:\Program Files\ConduitEngine\ConduitEngine.dll" CheckResult="-1"  Descr="Conduit Toolbar"  LegalCopyright="Copyright © Conduit Ltd. 2008."  UsedBy="1932,3416" Hidden="0" Size="3863136" Attr="rsAh" CreateDate="30.09.2010 00:30:15" ChageDate="12.09.2010 15:02:22" MD5="895C4812245E244B2F81C71BAD0C4E55" />
  <ITEM File="C:\Program Files\AlterGeo\AlterGeo Magic Scanner\2.8.8.615\AlterGeo.BrowserPlugin.dll" CheckResult="-1"  Descr="AlterGeo browser helper object"  LegalCopyright="Copyright (C) 2008-2009 Wi2Geo"  UsedBy="1932,3416" Hidden="0" Size="257384" Attr="rsAh" CreateDate="31.08.2010 17:15:44" ChageDate="31.08.2010 17:15:44" MD5="A4D8624275B52129436C48F6A35FD355" />
  <ITEM File="C:\WINDOWS\system32\Wlanapi.dll" CheckResult="-1"  Descr="Windows Wireless LAN 802.11 Client Side API DLL"  LegalCopyright="© Microsoft Corporation. All rights reserved."  UsedBy="1932,3416" Hidden="0" Size="69120" Attr="rsAh" CreateDate="04.11.2009 19:22:31" ChageDate="01.11.2006 11:17:36" MD5="AE860EF9FE7CE4E4A4645D05C269D8FB" />
  <ITEM File="C:\Program Files\Conduit\Community Alerts\Alert0.dll" CheckResult="-1"  Descr="Conduit Community Alerts"  LegalCopyright="Copyright © Conduit Ltd. 2008"  UsedBy="1932" Hidden="0" Size="546304" Attr="rsAh" CreateDate="22.12.2010 00:00:02" ChageDate="16.11.2010 10:24:20" MD5="434C446A2048AACAFFF49CFDF7839054" />
  <ITEM File="C:\Documents and Settings\Fenix\Local Settings\Application Data\uTorrentBar\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.1.1\bin\PriceGongIE.dll" CheckResult="-1"  Descr="PriceGong Comparative Shopping Tool"  LegalCopyright="PriceGong"  UsedBy="1932,3416" Hidden="0" Size="361848" Attr="rsAh" CreateDate="31.05.2010 04:27:14" ChageDate="31.05.2010 04:27:14" MD5="2B5514D946A43AFA9DB880F0562277CA" />
  <ITEM File="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll" CheckResult="-1"  Descr="Adobe PDF Helper for Internet Explorer"  LegalCopyright="Copyright 1984-2010 Adobe Systems Incorporated and its licensors. All rights reserved."  UsedBy="1932,3416" Hidden="0" Size="75200" Attr="rsAh" CreateDate="22.09.2010 19:04:14" ChageDate="22.09.2010 19:04:14" MD5="203A74767EB81F96A5166B1933DB46D0" />
  <ITEM File="C:\Program Files\Conduit\Community Alerts\Alert1.dll" CheckResult="-1"  Descr="Alert"  LegalCopyright="Copyright i?? Conduit Ltd. 2008."  UsedBy="3416" Hidden="0" Size="634976" Attr="rsAh" CreateDate="15.05.2011 19:27:06" ChageDate="15.05.2011 19:27:07" MD5="775D1655DCEF4AA65EBF89E744E511A0" />
 </DLL>
 <KERNELOBJ>
  <ITEM File="C:\WINDOWS\system32\drivers\drwebaf.sys" CheckResult="-1" Base="B75B1000" MemSize="014000" Descr="Dr.Web Application Filter Driver" LegalCopyright="© Doctor Web, Ltd., 1992-2010" Size="84728" Attr="rsAh" CreateDate="08.05.2011 14:00:42" ChageDate="08.05.2011 13:59:32" MD5="B5DC0A7A807C419CDB6398A014788FC0" />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\DrWebPF.sys" CheckResult="-1" Base="B9D4E000" MemSize="011000" Descr="Dr.Web Packet Filter Driver" LegalCopyright="© Doctor Web, Ltd., 1992-2010" Size="72568" Attr="rsAh" CreateDate="08.05.2011 14:00:45" ChageDate="08.05.2011 13:59:33" MD5="31CA09A3F6C8817E399A3C934565C8BA" />
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="B748D000" MemSize="018000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS" CheckResult="-1" Base="BADCA000" MemSize="002000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys" CheckResult="-1" Base="BA597000" MemSize="021000" Descr="Dr.Web Protection for Windows" LegalCopyright="Copyright Doctor Web, Ltd., 1992-2011" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F" />
  <ITEM File="\Program Files\DAEMON Tools Lite\Engine.dll" CheckResult="-1" Base="10000000" MemSize="246000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\System32\nv4_disp.dll" CheckResult="-1" Base="BF9D4000" MemSize="3BA000" Descr="NVIDIA Compatible Windows 2000 Display driver, Version 81.40 " LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Size="3903616" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="DAD1D2951DD012991981322773FB7233" />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\nv4_mini.sys" CheckResult="-1" Base="BA10C000" MemSize="358000" Descr="NVIDIA Compatible Windows 2000 Miniport Driver, Version 81.40 " LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Size="3502176" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="C9BAD8BE5F995B96F64BFEDA11F86348" />
  <ITEM File="spbt.sys" CheckResult="-1" Base="BA6B4000" MemSize="0F3000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\WINDOWS\system32\Drivers\spiderg3.sys" CheckResult="-1" Base="BA5B8000" MemSize="016000" Descr="Dr.Web File System Monitor" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="93944" Attr="rsAh" CreateDate="29.04.2011 22:09:36" ChageDate="31.01.2011 15:41:52" MD5="8F683D6AAC09B0F8C15E4D2D6728758C" />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\tcpip.sys" CheckResult="-1" Base="B75C5000" MemSize="059000" Descr="TCP/IP Protocol Driver" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="360576" Attr="rsAh" CreateDate="23.12.2006 00:40:21" ChageDate="23.12.2006 00:40:21" MD5="1DD47B236399BD231E0F0D1017FEBE8A" />
 </KERNELOBJ>
 <Service>
  <ITEM File="C:\Program Files\Bonjour\mDNSResponder.exe" Name="Bonjour Service" CheckResult="-1" Type="16" State="4" Size="345376" Attr="rsAh" CreateDate="07.10.2010 12:23:00" ChageDate="07.10.2010 12:23:00" MD5="F832F1505AD8B83474BD9A5B1B985E01"  />
  <ITEM File="C:\WINDOWS\system32\CSHelper.exe" Name="CSHelper" CheckResult="-1" Type="16" State="4" Size="266240" Attr="rsAh" CreateDate="06.12.2010 23:44:25" ChageDate="06.12.2010 23:44:25" MD5="AEFB8558199BD5212B268B09BFA1D71A"  />
  <ITEM File="C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe" Name="DrWebEngine" CheckResult="-1" Type="16" State="4" Size="1667416" Attr="rsAh" CreateDate="01.03.2011 16:48:36" ChageDate="01.03.2011 16:48:36" MD5="1F40F2B44E88E4719BBB5F71D996C6AF"  />
  <ITEM File="C:\Program Files\DrWeb\frwl_svc.exe" Name="DrWebFwSvc" CheckResult="-1" Type="16" State="4" Size="2267120" Attr="rsAh" CreateDate="08.05.2011 14:01:17" ChageDate="20.04.2011 15:25:06" MD5="A58C270D36E45910077B6E178323B440"  />
  <ITEM File="C:\WINDOWS\system32\nvsvc32.exe" Name="NVSvc" CheckResult="-1" Type="16" State="4" Size="131138" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="E64C56655F0ED9E595007997B47544B9"  />
  <ITEM File="AVP.sys" Name="AVP" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="gupdate1ca97c45b5e7382.sys" Name="gupdate1ca97c45b5e7382" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="NBService.sys" Name="NBService" CheckResult="-1" Type="272" State="1"   />
  <ITEM File="C:\WINDOWS\system32\GameMon.des" Name="npggsvc" CheckResult="-1" Type="272" State="1" Size="3432444" Attr="rsAh" CreateDate="19.06.2010 16:42:24" ChageDate="25.02.2010 00:01:00" MD5="59416EE7AFCA7669E51A1183C70C1AED"  />
  <ITEM File="C:\Program Files\QipGuard\QipGuard.exe" Name="QipGuard" CheckResult="-1" Type="16" State="1"   />
  <ITEM File="C:\Program Files\mediabar Toolbar\RubarUpdateService.exe" Name="Rubar Update Service" CheckResult="-1" Type="16" State="1"   />
 </Service>
 <Drivers>
  <ITEM File="C:\WINDOWS\system32\drivers\drwebaf.sys" Name="DRWEBAF" CheckResult="-1" Type="1" State="4" Size="84728" Attr="rsAh" CreateDate="08.05.2011 14:00:42" ChageDate="08.05.2011 13:59:32" MD5="B5DC0A7A807C419CDB6398A014788FC0"  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\DrWebPF.sys" Name="DrWebPF" CheckResult="-1" Type="1" State="4" Size="72568" Attr="rsAh" CreateDate="08.05.2011 14:00:45" ChageDate="08.05.2011 13:59:33" MD5="31CA09A3F6C8817E399A3C934565C8BA"  />
  <ITEM File="C:\WINDOWS\system32\drivers\dwprot.sys" Name="DwProt" CheckResult="-1" Type="2" State="4" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\nv4_mini.sys" Name="nv" CheckResult="-1" Type="1" State="4" Size="3502176" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="C9BAD8BE5F995B96F64BFEDA11F86348"  />
  <ITEM File="C:\WINDOWS\system32\drivers\spiderg3.sys" Name="SpiderG3" CheckResult="-1" Type="2" State="4" Size="93944" Attr="rsAh" CreateDate="29.04.2011 22:09:36" ChageDate="31.01.2011 15:41:52" MD5="8F683D6AAC09B0F8C15E4D2D6728758C"  />
  <ITEM File="C:\WINDOWS\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="691696" Attr="rsAh" CreateDate="04.11.2009 20:33:55" ChageDate="26.02.2010 17:11:18" MD5=""  />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\tcpip.sys" Name="Tcpip" CheckResult="-1" Type="1" State="4" Size="360576" Attr="rsAh" CreateDate="23.12.2006 00:40:21" ChageDate="23.12.2006 00:40:21" MD5="1DD47B236399BD231E0F0D1017FEBE8A"  />
  <ITEM File="sym_hi.sys" Name="sym_hi" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="sym_u3.sys" Name="sym_u3" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Abiosdsk.sys" Name="Abiosdsk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="abp480n5.sys" Name="abp480n5" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="adpu160m.sys" Name="adpu160m" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Aha154x.sys" Name="Aha154x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78u2.sys" Name="aic78u2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="aic78xx.sys" Name="aic78xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="AliIde.sys" Name="AliIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="amsint.sys" Name="amsint" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc.sys" Name="asc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3350p.sys" Name="asc3350p" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="asc3550.sys" Name="asc3550" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Atdisk.sys" Name="Atdisk" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\blueletaudio.sys" Name="BlueletAudio" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys" Name="BlueletSCOAudio" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="bnzbicpmb" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="bphbrzl" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="brrvacope" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\btnetdrv.sys" Name="BT" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\drivers\btaudio.sys" Name="btaudio" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\Drivers\btcusb.sys" Name="Btcsrusb" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\btport.sys" Name="BTDriver" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\System32\Drivers\vbtenum.sys" Name="BTHidEnum" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\System32\Drivers\BTHidMgr.sys" Name="BTHidMgr" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\btwdndis.sys" Name="BTWDNDIS" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\btwhid.sys" Name="btwhid" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="cbxqvurds" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="cd20xrnt.sys" Name="cd20xrnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Changer.sys" Name="Changer" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="CmdIde.sys" Name="CmdIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Cpqarray.sys" Name="Cpqarray" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dac960nt.sys" Name="dac960nt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="deltzis" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="dpti2o.sys" Name="dpti2o" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt" Name="EverestDriver" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="fgzsztsi" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="E:\Fxdrv.sys" Name="FXDRV" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\0D.tmp" Name="gbqgets" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="gdmcixu" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="gtblqtiqb" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="hpn.sys" Name="hpn" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="hsujxp" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omgmt.sys" Name="i2omgmt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="i2omp.sys" Name="i2omp" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ini910u.sys" Name="ini910u" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="IntelIde.sys" Name="IntelIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="jgutjtz" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="jlpvsuq" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\087.tmp" Name="jqrrtqlie" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="kfhlkwo" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="kgdmxoynh" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="lbrtfdc.sys" Name="lbrtfdc" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="lfjooha" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="mraid35x.sys" Name="mraid35x" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="nubpz" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PCIDump.sys" Name="PCIDump" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDCOMP.sys" Name="PDCOMP" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDFRAME.sys" Name="PDFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRELI.sys" Name="PDRELI" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="PDRFRAME.sys" Name="PDRFRAME" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2.sys" Name="perc2" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="perc2hib.sys" Name="perc2hib" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1080.sys" Name="ql1080" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Ql10wnt.sys" Name="Ql10wnt" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql12160.sys" Name="ql12160" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1240.sys" Name="ql1240" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ql1280.sys" Name="ql1280" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="rbfunzf" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="SASDIFSV.sys" Name="SASDIFSV" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="SASENUM.sys" Name="SASENUM" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="SASKUTIL.sys" Name="SASKUTIL" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Simbad.sys" Name="Simbad" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="Sparrow.sys" Name="Sparrow" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc810.sys" Name="symc810" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="symc8xx.sys" Name="symc8xx" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="TCPZ.sys" Name="TCPZ" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="TosIde.sys" Name="TosIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ultra.sys" Name="ultra" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\DRIVERS\VComm.sys" Name="VComm" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\Drivers\VcommMgr.sys" Name="VcommMgr" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\drivers\VHIDMini.sys" Name="VHidMinidrv" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="ViaIde.sys" Name="ViaIde" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="voomjgl" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="WDICA.sys" Name="WDICA" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\XDva349.sys" Name="XDva349" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\XDva366.sys" Name="XDva366" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\XDva370.sys" Name="XDva370" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="ximiu" CheckResult="-1" Type="1" State="1"   />
  <ITEM File="C:\WINDOWS\system32\01.tmp" Name="ycfxiougt" CheckResult="-1" Type="1" State="1"   />
 </Drivers>
 <AUTORUN>
  <ITEM File="C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll" CheckResult="-1" Enabled="-1" Type="REG" Size="59904" Attr="rsAh" CreateDate="12.04.2011 08:53:12" ChageDate="12.04.2011 08:53:12" MD5="81EC3155BE3E324A759AE81F2B904242" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\Windows" X3="AppInit_DLLs" />
  <ITEM File="C:\Documents and Settings\Fenix\Application Data\QipGuard\QipGuard.exe" CheckResult="-1" Enabled="1" Type="REG" Size="187776" Attr="rsAh" CreateDate="29.12.2010 03:55:44" ChageDate="01.02.2011 11:24:44" MD5="355F0F3B1C7CBED577D89A6FE437C6C6" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="QIP Internet Guardian" />
  <ITEM File="C:\Documents and Settings\Fenix\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="1004088" Attr="rsAh" CreateDate="12.05.2011 11:59:49" ChageDate="13.04.2011 03:51:02" MD5="1BB21F4C2573A13B9A7E1FC7A4215109" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk" X3="" />
  <ITEM File="C:\Documents and Settings\Fenix\Local Settings\Application Data\MediaGet2\mediaget.exe" CheckResult="-1" Enabled="1" Type="REG" Size="6053096" Attr="rsAh" CreateDate="25.04.2011 21:31:08" ChageDate="22.04.2011 17:19:16" MD5="C55C90F4D013B00A4427760E6715484A" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="MediaGet2" />
  <ITEM File="C:\Documents and Settings\Fenix\Local Settings\Application Data\MediaGet2\mediaget.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="6053096" Attr="rsAh" CreateDate="25.04.2011 21:31:08" ChageDate="22.04.2011 17:19:16" MD5="C55C90F4D013B00A4427760E6715484A" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaGet.lnk" X3="" />
  <ITEM File="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" CheckResult="-1" Enabled="1" Type="REG" Size="35760" Attr="rsAh" CreateDate="23.09.2010 05:47:04" ChageDate="23.09.2010 05:47:04" MD5="12673BCF7B32087DF63F0CFF550EA40B" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Adobe Reader Speed Launcher" />
  <ITEM File="C:\Program Files\Bonjour\mDNSResponder.exe" CheckResult="-1" Enabled="-1" Type="REG" Size="345376" Attr="rsAh" CreateDate="07.10.2010 12:23:00" ChageDate="07.10.2010 12:23:00" MD5="F832F1505AD8B83474BD9A5B1B985E01" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe" CheckResult="-1" Enabled="-1" Type="REG" Size="1667416" Attr="rsAh" CreateDate="01.03.2011 16:48:36" ChageDate="01.03.2011 16:48:36" MD5="1F40F2B44E88E4719BBB5F71D996C6AF" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Doctor Web\Dr.Web Engine" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\Daphne\Daphne.exe" CheckResult="-1" Enabled="1" Type="REG" Size="813568" Attr="rsAh" CreateDate="28.08.2010 18:30:04" ChageDate="28.08.2010 18:30:04" MD5="B6FFC8F6077B5D6C0CE791451DB41C62" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="LHFDaphne" />
  <ITEM File="C:\Program Files\DrWeb\drwsxtn.dll" CheckResult="-1" Enabled="1" Type="REG" Size="88616" Attr="rsAh" CreateDate="16.03.2011 17:09:50" ChageDate="16.03.2011 17:09:50" MD5="429FCDDCE00EC4961655DD57B2EF3DFE" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{E7593602-124B-47C9-9F73-A69308EDC973}" />
  <ITEM File="C:\Program Files\DrWeb\frwl_svc.exe" CheckResult="-1" Enabled="-1" Type="REG" Size="2267120" Attr="rsAh" CreateDate="08.05.2011 14:01:17" ChageDate="20.04.2011 15:25:06" MD5="A58C270D36E45910077B6E178323B440" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\DrWebFWSvc" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\DrWeb\spideragent.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="1473264" Attr="rsAh" CreateDate="16.03.2011 17:11:12" ChageDate="20.04.2011 15:33:01" MD5="5EF1D63BAF30654E0A8619A993CA1D7C" X1="C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\" X2="C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\Dr.Web ®.lnk" X3="" />
  <ITEM File="C:\Program Files\DrWeb\spiderml.exe" CheckResult="-1" Enabled="1" Type="REG" Size="1572592" Attr="rsAh" CreateDate="16.03.2011 17:11:28" ChageDate="16.03.2011 17:11:28" MD5="23EB2DA12DCE9E5A3CA58BBA22A01072" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="SpIDerMail" />
  <ITEM File="C:\Program Files\Opera\opera.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="941936" Attr="rsAh" CreateDate="28.01.2011 13:43:13" ChageDate="14.04.2011 17:13:37" MD5="A1751C5FB748F3408093EC26D447856A" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk" X3="" />
  <ITEM File="C:\Program Files\QIP 2010\qip.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="5969280" Attr="rsAh" CreateDate="29.12.2010 03:52:58" ChageDate="01.02.2011 11:24:50" MD5="55A2D2B58081BFCDF2FBFB81F4097B0C" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\QIP 2010.lnk" X3="" />
  <ITEM File="C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" CheckResult="-1" Enabled="1" Type="REG" Size="1527808" Attr="rsAh" CreateDate="29.11.2010 18:14:44" ChageDate="29.11.2010 18:14:44" MD5="E000AD225650695DA6FCD112891DFBE5" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls" X3="QuickTime" />
  <ITEM File="C:\Program Files\QuickTime\QTTask.exe" CheckResult="-1" Enabled="1" Type="REG" Size="421888" Attr="rsAh" CreateDate="29.11.2010 17:38:18" ChageDate="29.11.2010 17:38:18" MD5="0AEE5668EB59912F32FF245BFA72465F" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="QuickTime Task" />
  <ITEM File="C:\Program Files\Revo Uninstaller Pro\RevoUninPro.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="11357120" Attr="rsAh" CreateDate="06.12.2010 12:46:29" ChageDate="04.11.2010 11:16:16" MD5="139AC452C9EE9FABBE0A4AF51C22594A" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk" X3="" />
  <ITEM File="C:\Program Files\Stocona\Sto" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\SAV_Firewall" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\uTorrent\uTorrent.exe" CheckResult="-1" Enabled="1" Type="REG" Size="399736" Attr="rsAh" CreateDate="18.08.2010 19:22:12" ChageDate="26.03.2011 12:24:21" MD5="276AC7BAE1F596A3A1D4B6D43AEF099C" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="uTorrent" />
  <ITEM File="C:\Program Files\uTorrent\uTorrent.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="399736" Attr="rsAh" CreateDate="18.08.2010 19:22:12" ChageDate="26.03.2011 12:24:21" MD5="276AC7BAE1F596A3A1D4B6D43AEF099C" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk" X3="" />
  <ITEM File="C:\WINDOWS\Installer\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}\SafariIco.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="897024" Attr="RsAh" CreateDate="13.05.2011 15:25:41" ChageDate="13.05.2011 15:25:41" MD5="A55E64922F7FF513AA8133E33F3E9704" X1="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk" X3="" />
  <ITEM File="C:\WINDOWS\System32\Drivers\AliIde.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\CmdIde.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\IntelIde.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\TosIde.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\toside" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\ViaIde.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\Drivers\lbrtfdc.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\PrintFilterPipelineSvc.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\drivers\btport.sys" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\BTDriver" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\drivers\dwprot.sys" CheckResult="-1" Enabled="-1" Type="REG" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\DwProt" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\drivers\nv4_mini.sys" CheckResult="-1" Enabled="-1" Type="REG" Size="3502176" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="C9BAD8BE5F995B96F64BFEDA11F86348" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\nv" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\igmpv2.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ipbootp.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\iprip2.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ospf.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\ospfmib.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\polagent.dll" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\System32\tssdis.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir" X3="EventMessageFile" />
  <ITEM File="C:\WINDOWS\system32\MsSip1.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\MsSip2.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\MsSip3.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3" X3="$DLL" />
  <ITEM File="C:\WINDOWS\system32\NvCpl.dll" CheckResult="-1" Enabled="1" Type="REG" Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="NvCplDaemon" />
  <ITEM File="C:\WINDOWS\system32\nvcpl.dll" CheckResult="-1" Enabled="1" Type="REG" Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{A70C977A-BF00-412C-90B7-034C51DA2439}" />
  <ITEM File="C:\WINDOWS\system32\nvcpl.dll" CheckResult="-1" Enabled="1" Type="REG" Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{FFB699E0-306A-11d3-8BD1-00104B6F7516}" />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" Type="REG" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{1CDB2949-8F65-4355-8456-263E7C208A5D}" />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" Type="REG" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" Type="REG" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" />
  <ITEM File="C:\WINDOWS\system32\psxss.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="System\CurrentControlSet\Control\Session Manager\SubSystems" X3="Posix" />
  <ITEM File="C:\WINDOWS\system32\stisvc.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System" X3="EventMessageFile" />
  <ITEM File="kbd101.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\i8042prt\Parameters" X3="LayerDriver JPN" />
  <ITEM File="kbd101a.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\i8042prt\Parameters" X3="LayerDriver KOR" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2=".DEFAULT\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-19\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-20\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_USERS" X2="S-1-5-18\Control Panel\IOProcs" X3="MVB" />
  <ITEM File="mvfs32.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_CURRENT_USER" X2="Control Panel\IOProcs" X3="MVB" />
  <ITEM File="nvoglnt.dll" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\RIVATNT" X3="DLL" />
  <ITEM File="vgafix.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fixedfon.fon" />
  <ITEM File="vgaoem.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="oemfonts.fon" />
  <ITEM File="vgasys.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fonts.fon" />
 </AUTORUN>
 <BHO>
  <ITEM File="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{18DF081C-E8AD-4283-A596-FA578C2EBDC3}" Descr="Adobe PDF Helper for Internet Explorer" LegalCopyright="Copyright 1984-2010 Adobe Systems Incorporated and its licensors. All rights reserved." Size="75200" Attr="rsAh" CreateDate="22.09.2010 19:04:14" ChageDate="22.09.2010 19:04:14" MD5="203A74767EB81F96A5166B1933DB46D0"  />
  <ITEM File="C:\Program Files\ConduitEngine\ConduitEngine.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{30F9B915-B755-4826-820B-08FBA6BD249D}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="3863136" Attr="rsAh" CreateDate="30.09.2010 00:30:15" ChageDate="12.09.2010 15:02:22" MD5="895C4812245E244B2F81C71BAD0C4E55"  />
  <ITEM File="C:\Program Files\digitalchocolate\prxtbdigi.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{60c4696a-e4eb-4d2d-9060-38928dd0b6a2}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="175400" Attr="rsAh" CreateDate="13.01.2011 16:47:15" ChageDate="03.01.2011 11:16:50" MD5="3A5627E0AB06F3CA7FB238CE5EE8CDF9"  />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{8984B388-A5BB-4DF7-B274-77B879E179DB}" Descr="" LegalCopyright=""   />
  <ITEM File="C:\Program Files\AlterGeo\AlterGeo Magic Scanner\2.8.8.615\AlterGeo.BrowserPlugin.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{9BFBA68E-E21B-458E-AE12-FE85E903D2C1}" Descr="AlterGeo browser helper object" LegalCopyright="Copyright (C) 2008-2009 Wi2Geo" Size="257384" Attr="rsAh" CreateDate="31.08.2010 17:15:44" ChageDate="31.08.2010 17:15:44" MD5="A4D8624275B52129436C48F6A35FD355"  />
  <ITEM File="C:\Program Files\uTorrentBar\tbuTo1.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="3911776" Attr="rsAh" CreateDate="13.01.2011 16:33:25" ChageDate="13.01.2011 16:33:39" MD5="D9A0CE26ADA5BD15B1B03A752DDF14A6"  />
  <ITEM File="C:\Program Files\ConduitEngine\ConduitEngine.dll" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{30F9B915-B755-4826-820B-08FBA6BD249D}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="3863136" Attr="rsAh" CreateDate="30.09.2010 00:30:15" ChageDate="12.09.2010 15:02:22" MD5="895C4812245E244B2F81C71BAD0C4E55"  />
  <ITEM File="C:\Program Files\digitalchocolate\prxtbdigi.dll" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{60c4696a-e4eb-4d2d-9060-38928dd0b6a2}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="175400" Attr="rsAh" CreateDate="13.01.2011 16:47:15" ChageDate="03.01.2011 11:16:50" MD5="3A5627E0AB06F3CA7FB238CE5EE8CDF9"  />
  <ITEM File="C:\Program Files\uTorrentBar\tbuTo1.dll" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}" Descr="Conduit Toolbar" LegalCopyright="Copyright © Conduit Ltd. 2008." Size="3911776" Attr="rsAh" CreateDate="13.01.2011 16:33:25" ChageDate="13.01.2011 16:33:39" MD5="D9A0CE26ADA5BD15B1B03A752DDF14A6"  />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{23DD83B5-BDDC-49CE-B77B-514819C6D551}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" CLSID="{8DAE90AD-4583-4977-9DD4-4360F7A45C74}" Descr="" LegalCopyright=""   />
 </BHO>
 <ExplorerExt>
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Расширение CPL панорамирования дисплея" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071714-76d4-11d1-8b24-00a0c9068ff3}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Расширения оболочки для сжатия файлов" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{764BF0E1-F219-11ce-972D-00AA00A14F56}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Контекстное меню шифрования" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Панель задач и меню @apos;@apos;Пуск@apos;@apos;" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0DF44EAA-FF21-4412-828E-260A8728E7F1}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Учетные записи пользователей" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7A9D77BD-5403-11d2-8785-2E0420524153}" Descr="" LegalCopyright=""   />
  <ITEM File="C:\WINDOWS\system32\nvcpl.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="NvCpl DesktopContext Class" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{A70C977A-BF00-412C-90B7-034C51DA2439}" Descr="NVIDIA Display Properties Extension" LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987"  />
  <ITEM File="C:\WINDOWS\system32\nvcpl.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Play on my TV helper" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{FFB699E0-306A-11d3-8BD1-00104B6F7516}" Descr="NVIDIA Display Properties Extension" LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Size="7196672" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="4998E00CA3BB3F52A937A6C07AC42987"  />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Desktop Explorer" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1CDB2949-8F65-4355-8456-263E7C208A5D}" Descr="" LegalCopyright="" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C"  />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Desktop Explorer Menu" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" Descr="" LegalCopyright="" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C"  />
  <ITEM File="C:\WINDOWS\system32\nvshell.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="nView Desktop Context Menu" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" Descr="" LegalCopyright="" Size="466944" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="6E1D3ABB456AAFF24A952F235E3C5A8C"  />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="IE User Assist" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Диспетчер файлов Sony Ericsson" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{03DAACC5-10BA-4E3E-9D54-2A569F6B4B87}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Диспетчер файлов Sony Ericsson" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{738D66C6-0149-4D40-84E4-A7BB2D0CE949}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Monitor" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7842554E-6BED-11D2-8CDB-B05550C10000}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Revo Uninstaller Pro Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{2C5515DC-2A7E-4BFD-B813-CACC2B685EB7}" Descr="" LegalCopyright=""   />
  <ITEM File="C:\Program Files\DrWeb\drwsxtn.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Shell Extension for DrWeb" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{E7593602-124B-47C9-9F73-A69308EDC973}" Descr="Dr.Web ® Shell Extension" LegalCopyright="© Doctor Web, Ltd., 1992-2011" Size="88616" Attr="rsAh" CreateDate="16.03.2011 17:09:50" ChageDate="16.03.2011 17:09:50" MD5="429FCDDCE00EC4961655DD57B2EF3DFE"  />
  <ITEM File="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" CheckResult="-1" Enabled="1" ExtType="2" ExtName="ColumnHandler" RegKey="SOFTWARE\Classes\Folder\shellex\ColumnHandlers" CLSID="{F9DB5320-233E-11D1-9F84-707F02C10627}" Descr="PDF Shell Extension" LegalCopyright="Copyright 2000-2010 Adobe Systems Incorporated and its licensors. All rights reserved." Size="378264" Attr="rsAh" CreateDate="22.09.2010 19:12:42" ChageDate="22.09.2010 19:12:42" MD5="FF575E76DA89A3CEDE920BB71EE2F3C7"  />
 </ExplorerExt>
 <PrintEXT>
 </PrintEXT>
 <TaskScheduler>
  <ITEM File="C:\Program Files\DrWeb\drweb32w.exe" CheckResult="-1" Enabled="49762336" Descr="Dr.Web© Scanner for Windows" LegalCopyright="(c) Doctor Web, Ltd., 1992-2011" Size="2283272" Attr="rsAh" CreateDate="16.03.2011 17:09:12" ChageDate="11.05.2011 13:39:32" MD5="83C7C7BDCB2C4C153357E97578F3DD03"  />
  <ITEM File="C:\Program Files\DrWeb\DrWebUpW.exe" CheckResult="-1" Enabled="49762336" Descr="Dr.Web Update for Windows" LegalCopyright="© Doctor Web, Ltd, 1992-2011" Size="1809672" Attr="rsAh" CreateDate="16.03.2011 17:11:52" ChageDate="07.04.2011 13:46:26" MD5="DF22DF5AF66395F4931460B5D0F9E7E2"  />
  <ITEM File="C:\Program Files\Google\Update\GoogleUpdate.exe" CheckResult="-1" Enabled="49762336" Descr="" LegalCopyright=""   />
  <ITEM File="C:\Program Files\Google\Update\GoogleUpdate.exe" CheckResult="-1" Enabled="49762336" Descr="" LegalCopyright=""   />
 </TaskScheduler>
 <SPI>
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="TCP/IP" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\System32\winrnr.dll" CheckResult="-1" SPIType="1" SPINaim="NTDS" Descr="LDAP RnR Provider DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="16896" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="852E8D4F6B83CAF662D199E79D5557EA"  />
  <ITEM File="C:\WINDOWS\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="Пространство имен службы сетевого расположения (NLA)" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\wshbth.dll" CheckResult="-1" SPIType="1" SPINaim="Пространство имен Bluetooth" Descr="Windows Sockets Helper DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="108032" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="4701970CD9E693D25104D8E442C53D10"  />
  <ITEM File="C:\Program Files\Bonjour\mdnsNSP.dll" CheckResult="-1" SPIType="1" SPINaim="mdnsNSP" Descr="Bonjour Namespace Provider" LegalCopyright="Copyright (C) 2003-2010 Apple Inc." Size="152864" Attr="rsAh" CreateDate="07.10.2010 12:23:00" ChageDate="07.10.2010 12:23:00" MD5="C69DBFA61FE3DEA653A9B83C3A2B052B"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4 over [MSAFD Tcpip [TCP/IP]]" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4 over [MSAFD Tcpip [UDP/IP]]" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4 over [MSAFD Tcpip [RAW/IP]]" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4 over [RSVP UDP Service Provider]" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4 over [RSVP TCP Service Provider]" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Irda [IrDA]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [TCP/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [UDP/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Tcpip [RAW/IP]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP UDP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="07078A8814E6DD87C27BB0D8A2163D23"  />
  <ITEM File="C:\WINDOWS\system32\rsvpsp.dll" CheckResult="-1" SPIType="3" SPINaim="RSVP TCP Service Provider" Descr="Microsoft Windows Rsvp 1.0 Service Provider" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="90112" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="07078A8814E6DD87C27BB0D8A2163D23"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD RfComm [Bluetooth]" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2E6D7E3-C862-4B75-B0BA-95E4ED407E99}] SEQPACKET 8" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2E6D7E3-C862-4B75-B0BA-95E4ED407E99}] DATAGRAM 8" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{32356C95-200D-4358-BDC4-86620316F38A}] SEQPACKET 7" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{32356C95-200D-4358-BDC4-86620316F38A}] DATAGRAM 7" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F978C4D9-3A3C-499F-A1CA-87CE811E7936}] SEQPACKET 6" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{F978C4D9-3A3C-499F-A1CA-87CE811E7936}] DATAGRAM 6" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{B43C0FDB-FBC4-4BC2-B660-F2400B4A24DD}] SEQPACKET 5" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{B43C0FDB-FBC4-4BC2-B660-F2400B4A24DD}] DATAGRAM 5" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{64D2E139-6189-4057-AFE8-46031EB94894}] SEQPACKET 0" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{64D2E139-6189-4057-AFE8-46031EB94894}] DATAGRAM 0" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{9243C997-94F5-4FEC-934F-0232148DE5F6}] SEQPACKET 1" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{9243C997-94F5-4FEC-934F-0232148DE5F6}] DATAGRAM 1" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{73C87C14-0ABA-486B-8A11-928374173D66}] SEQPACKET 2" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{73C87C14-0ABA-486B-8A11-928374173D66}] DATAGRAM 2" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{16CF5E63-B785-4E0E-BD57-95740F965C81}] SEQPACKET 3" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{16CF5E63-B785-4E0E-BD57-95740F965C81}] DATAGRAM 3" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{E485C9CB-765E-4734-B329-A7452969358E}] SEQPACKET 4" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\WINDOWS\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{E485C9CB-765E-4734-B329-A7452969358E}] DATAGRAM 4" Descr="Расширение поставщика службы API Microsoft Windows Sockets 2.0" LegalCopyright="© Корпорация Майкрософт. Все права защищены." Size="247296" Attr="rsAh" CreateDate="18.08.2003 00:00:00" ChageDate="18.08.2003 00:00:00" MD5="25569F8A60B11208233B86D707765FAD"  />
  <ITEM File="C:\Program Files\DrWeb\drwebsp.dll" CheckResult="-1" SPIType="3" SPINaim="DrWebSP.4" Descr="Dr.Web Winsock Provider Hook" LegalCopyright="Copyright (c) Doctor Web, Ltd., 1992-2011" Size="161520" Attr="rsAh" CreateDate="16.03.2011 17:04:06" ChageDate="11.05.2011 13:39:32" MD5="1CCF27F5E047CF4A192A277B1397F41A"  />
 </SPI>
 <DPF>
 </DPF>
 <CPL>
  <ITEM File="C:\WINDOWS\system32\FlashPlayerCPLApp.cpl" CheckResult="-1" Enabled="1" Descr="Adobe Flash Player Control Panel Applet" LegalCopyright="Copyright © 1996-2010 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries." Size="404640" Attr="rsAh" CreateDate="13.05.2011 16:03:22" ChageDate="13.05.2011 16:03:22" MD5="CE517C148FB9E1BD20663A4665E1C5D3"  />
  <ITEM File="C:\WINDOWS\system32\nvcpl.cpl" CheckResult="-1" Enabled="1" Descr="NVIDIA nvCpl Control Panel Applet 1.0.0.6" LegalCopyright="(C) NVIDIA Corporation. All rights reserved." Size="65536" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="701933F9AC0972E87D5BB9FFB8B928CF"  />
  <ITEM File="C:\WINDOWS\system32\nvtuicpl.cpl" CheckResult="-1" Enabled="1" Descr="" LegalCopyright="" Size="73728" Attr="rsAh" CreateDate="16.08.2005 17:43:00" ChageDate="16.08.2005 17:43:00" MD5="F0FD39B71CC57EC42F6C742F92B057F2"  />
 </CPL>
 <ActiveSetup>
 </ActiveSetup>
 <HOSTS>
 </HOSTS>
 <ProtocolExt>
  <ITEM File="mscoree.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/octet-stream" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation.  All rights reserved."   />
  <ITEM File="mscoree.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/x-complus" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation.  All rights reserved."   />
  <ITEM File="mscoree.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/x-msdownload" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation.  All rights reserved."   />
  <ITEM File="C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Classes\PROTOCOLS\Handler\skype4com" CLSID="{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}" Descr="Skype for COM API" LegalCopyright="(c) Skype Technologies.  All rights reserved." Size="2164104" Attr="RsAh" CreateDate="11.10.2010 17:49:48" ChageDate="11.10.2010 17:49:48" MD5="FB0A62DBDF98A5466105D19B199C83BF"  />
 </ProtocolExt>
 <SuspFiles>
  <ITEM File="C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll" VirType="5" Descr="Подозрение на Keylogger или троянскую DLL"  />
  <ITEM File="C:\Program Files\Daphne\DRKHooks.dll" VirType="5" Descr="Подозрение на Keylogger или троянскую DLL"  />
  <ITEM File="C:\WINDOWS\system32\system" VirType="3" Descr=" ЭПС: подозрение на Файл с подозрительным именем (CH) (высокая степень вероятности)"  />
 </SuspFiles>
 <RK_KM>
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtAllocateVirtualMemory" FIndx="17" HookPtr="BA5ABD90" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys"  FNaim="NtClose" FIndx="25" HookPtr="BAC418A0" HookType="1" CheckResult="0" Size="27280" Attr="RsAh" CreateDate="13.11.2007 00:00:00" ChageDate="13.11.2007 00:00:00" MD5="F514268EDB3B03883F7A5151F49BF229"/>
  <ITEM File="spbt.sys"  FNaim="NtCreateKey" FIndx="41" HookPtr="BA6B50E0" HookType="1" />
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtCreateThread" FIndx="53" HookPtr="BA5AD1E4" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="spbt.sys"  FNaim="NtEnumerateKey" FIndx="71" HookPtr="BA6CDDA4" HookType="1" />
  <ITEM File="spbt.sys"  FNaim="NtEnumerateValueKey" FIndx="73" HookPtr="BA6CE132" HookType="1" />
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtFreeVirtualMemory" FIndx="83" HookPtr="BA5AC00E" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="spbt.sys"  FNaim="NtOpenKey" FIndx="119" HookPtr="BA6B50C0" HookType="1" />
  <ITEM File="C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys"  FNaim="NtOpenProcess" FIndx="122" HookPtr="BAC418D0" HookType="1" CheckResult="0" Size="27280" Attr="RsAh" CreateDate="13.11.2007 00:00:00" ChageDate="13.11.2007 00:00:00" MD5="F514268EDB3B03883F7A5151F49BF229"/>
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtOpenSection" FIndx="125" HookPtr="BA5ABBAE" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="spbt.sys"  FNaim="NtQueryKey" FIndx="160" HookPtr="BA6CE20A" HookType="1" />
  <ITEM File="spbt.sys"  FNaim="NtQueryValueKey" FIndx="177" HookPtr="BA6CE08A" HookType="1" />
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtQueueApcThread" FIndx="180" HookPtr="BA5AD2E6" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtSetContextThread" FIndx="213" HookPtr="BA5AD332" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="spbt.sys"  FNaim="NtSetValueKey" FIndx="247" HookPtr="BA6CE29C" HookType="1" />
  <ITEM File="C:\WINDOWS\system32\Drivers\dwprot.sys"  FNaim="NtSystemDebugControl" FIndx="255" HookPtr="BA5ABAC4" HookType="1" CheckResult="-1" Size="139768" Attr="rsAh" CreateDate="29.04.2011 22:24:36" ChageDate="03.02.2011 15:05:03" MD5="249A3ED0B70E4ABA4D11C9F07A10209F"/>
  <ITEM File="C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys"  FNaim="NtTerminateProcess" FIndx="257" HookPtr="BAC41980" HookType="1" CheckResult="0" Size="27280" Attr="RsAh" CreateDate="13.11.2007 00:00:00" ChageDate="13.11.2007 00:00:00" MD5="F514268EDB3B03883F7A5151F49BF229"/>
  <ITEM File="C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys"  FNaim="NtTerminateThread" FIndx="258" HookPtr="BAC41A20" HookType="1" CheckResult="0" Size="27280" Attr="RsAh" CreateDate="13.11.2007 00:00:00" ChageDate="13.11.2007 00:00:00" MD5="F514268EDB3B03883F7A5151F49BF229"/>
  <ITEM File="C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys"  FNaim="NtWriteVirtualMemory" FIndx="277" HookPtr="BAC41AC0" HookType="1" CheckResult="0" Size="27280" Attr="RsAh" CreateDate="13.11.2007 00:00:00" ChageDate="13.11.2007 00:00:00" MD5="F514268EDB3B03883F7A5151F49BF229"/>
 </RK_KM>
 <IPU>
  <ITEM Code="1" X1="RemoteRegistry" X2="Удаленный реестр" />
  <ITEM Code="1" X1="TermService" X2="Службы терминалов" />
  <ITEM Code="1" X1="SSDPSRV" X2="Служба обнаружения SSDP" />
  <ITEM Code="1" X1="TlntSvr" X2="Telnet" />
  <ITEM Code="1" X1="Alerter" X2="Оповещатель" />
  <ITEM Code="1" X1="Schedule" X2="Планировщик заданий" />
  <ITEM Code="1" X1="mnmsrvc" X2="NetMeeting Remote Desktop Sharing" />
  <ITEM Code="1" X1="RDSessMgr" X2="Диспетчер сеанса справки для удаленного рабочего стола" />
  <ITEM Code="3" />
  <ITEM Code="5" />
  <ITEM Code="8" X1="1" />
  <ITEM Code="1" X1="RemoteRegistry" X2="Удаленный реестр" />
  <ITEM Code="1" X1="TermService" X2="Службы терминалов" />
  <ITEM Code="1" X1="SSDPSRV" X2="Служба обнаружения SSDP" />
  <ITEM Code="1" X1="TlntSvr" X2="Telnet" />
  <ITEM Code="1" X1="Alerter" X2="Оповещатель" />
  <ITEM Code="1" X1="Schedule" X2="Планировщик заданий" />
  <ITEM Code="1" X1="mnmsrvc" X2="NetMeeting Remote Desktop Sharing" />
  <ITEM Code="1" X1="RDSessMgr" X2="Диспетчер сеанса справки для удаленного рабочего стола" />
  <ITEM Code="3" />
  <ITEM Code="5" />
  <ITEM Code="8" X1="1" />
 </IPU>
 <RK_IRP>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="0" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="2" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="4" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="5" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="6" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="7" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="8" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="10" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="11" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="12" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="13" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="14" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="17" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="20" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="21" HookPtr="8A7E31F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="27" HookPtr="8A7E31F8"/>
 </RK_IRP>
 <KEYLOGGER>
  <ITEM File="C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll"  Verdict="" CheckResult="-1" Size="59904" Attr="rsAh" CreateDate="12.04.2011 08:53:12" ChageDate="12.04.2011 08:53:12" MD5="81EC3155BE3E324A759AE81F2B904242"/>
  <ITEM File="C:\Program Files\Daphne\DRKHooks.dll"  Verdict="Реагирует на события: клавиатура" CheckResult="-1" Size="43008" Attr="rsAh" CreateDate="17.06.2010 02:32:18" ChageDate="17.06.2010 02:32:18" MD5="A782256B899F259BA0DD7DA0F18907A5"/>
 </KEYLOGGER>
</AVZ>
