<?xml version="1.0" encoding="windows-1251" ?>
<AVZ Version="4.39" LogDate="11.01.2013 14:08:22" WinDir="C:\Windows\" OS_MjVer="6" OS_MiVer="1" OS_Build="7600" BootMode="0" OS_CSDV="" ProfileDir="C:\Users\Àäìèíèñòðàòîð" Session="Console" Domain="WORKGROUP" IsWow64="False" IsAdmin="True" Base64Mode="False" IsSRDisabled="False" MainDBDate="20.05.2012" CompHash="AAD7F6207D0A4ADEE05B21C9A704EF6A">
 <PROCESS>
  <ITEM PID="3844" File="c:\users\Àäìèíèñòðàòîð\appdata\roaming\7c.exe" CheckResult="-1" Descr="On-Demand Scanner" LegalCopyright="Copyright © 2000 - 2010 Avira GmbH. All rights reserved." Hidden="0"  CmdLine="&quot;C:\Windows\explorer.exe&quot;" Size="302912" Attr="rsAh" CreateDate="06.01.2013 06:13:43" ChangeDate="06.01.2013 06:13:43" MD5="B2DEF58915E5A846921A7D3A895ECB56" Vendor="Avira GmbH" Product="AntiVir Desktop" OFN="avscan.exe" NationalName="Y" />
  <ITEM PID="3992" File="c:\users\Àäìèíèñòðàòîð\appdata\roaming\7c.exe" CheckResult="-1" Descr="On-Demand Scanner" LegalCopyright="Copyright © 2000 - 2010 Avira GmbH. All rights reserved." Hidden="0"  CmdLine="dsdmappedod.exe -a 59 -g yes -o http://www.ewgtr.us:443/ -u m2n3r_A -p refiuvytre" Size="302912" Attr="rsAh" CreateDate="06.01.2013 06:13:43" ChangeDate="06.01.2013 06:13:43" MD5="B2DEF58915E5A846921A7D3A895ECB56" Vendor="Avira GmbH" Product="AntiVir Desktop" OFN="avscan.exe" NationalName="Y" />
  <ITEM PID="3044" File="c:\windows\8 skin pack\aura\aura.exe" CheckResult="-1" Descr="Aura" LegalCopyright="Copyright © Stealth 2011" Hidden="0"  CmdLine="&quot;C:\Windows\8 Skin Pack\Aura\Aura.exe&quot; " Size="471040" Attr="rsAh" CreateDate="12.04.2011 15:14:00" ChangeDate="12.04.2011 15:14:00" MD5="B13404D4770A8590409A22288F47AF3E" Vendor="Stealth Software" Product="Aura" OFN="Aura.exe" />
  <ITEM PID="1768" File="c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe" CheckResult="0" Descr="Kaspersky Anti-Virus" LegalCopyright="© 1997-2010 Kaspersky Lab ZAO." Hidden="0"  CmdLine="" Size="365336" Attr="rsAh" CreateDate="02.11.2010 21:06:06" ChangeDate="02.11.2010 21:06:06" MD5="B2B3FCBA37671C853879DF7DDE8A839A" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="AVP.EXE" />
  <ITEM PID="2420" File="c:\windows\explorer.exe" CheckResult="-1" Descr="Ïðîâîäíèê" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Hidden="0"  CmdLine="C:\Windows\Explorer.EXE" Size="2614784" Attr="rsAh" CreateDate="21.10.2012 10:57:45" ChangeDate="26.02.2011 07:33:07" MD5="1BBFD46740A483DEBA926FDA1A034613" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="EXPLORER.EXE.MUI" />
  <ITEM PID="2664" File="c:\program files\svyaznoy modem\modemlistener.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="&quot;C:\Program Files\Svyaznoy Modem\ModemListener.exe&quot; start" Size="98304" Attr="rsAh" CreateDate="20.03.2012 21:02:10" ChangeDate="31.03.2011 11:16:24" MD5="C5356FCE3BC8E685DE0C111D22FA85DA" />
  <ITEM PID="2804" File="c:\program files\ticno\multibar\multibar.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="&quot;C:\Program Files\Ticno\Multibar\multibar.exe&quot; /auto" Size="510976" Attr="rsAh" CreateDate="26.01.2012 01:38:20" ChangeDate="26.01.2012 01:38:20" MD5="F9302AE9695DA98457E9E86768796F8A" />
  <ITEM PID="2876" File="c:\progra~1\ticno\multibar\multibar_main.exe" CheckResult="0" Descr="multibar Application" LegalCopyright="Copyright (C) 2010" Hidden="0"  CmdLine="&quot;C:\PROGRA~1\Ticno\Multibar\multibar_main.exe&quot; 66122" Size="1997824" Attr="rsAh" CreateDate="17.08.2011 15:45:36" ChangeDate="17.08.2011 15:45:36" MD5="957E9EE5095590B8E7F6DF1C4F50F664" Product="multibar Application" OFN="multibar.exe" />
  <ITEM PID="5232" File="c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe" CheckResult="0" Descr="PresentationFontCache.exe" LegalCopyright="© Microsoft Corporation.  All rights reserved." Hidden="0"  CmdLine="C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe" Size="42856" Attr="rsAh" CreateDate="14.07.2009 02:35:50" ChangeDate="10.06.2009 23:14:51" MD5="E56F39F6B7FDA0AC77A79B0FD3DE1A2F" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="PresentationFontCache.exe" />
  <ITEM PID="1028" File="c:\program files\ticno\indexator\searchservice.exe" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="&quot;C:\Program Files\Ticno\Indexator\SearchService.exe&quot;" Size="517632" Attr="rsAh" CreateDate="10.05.2012 12:18:38" ChangeDate="10.05.2012 12:18:38" MD5="4E74CCB023265BDA0936F264EFBF43D7" />
  <ITEM PID="3884" File="c:\users\Àäìèíèñòðàòîð\appdata\local\skymonk2\skymonk2.bin" CheckResult="-1" Descr="" LegalCopyright="" Hidden="0"  CmdLine="&quot;C:\Users\Àäìèíèñòðàòîð\AppData\Local\Skymonk2\skymonk2.bin&quot; -tray" Size="359056" Attr="rsAh" CreateDate="20.09.2012 15:12:52" ChangeDate="10.01.2012 16:48:14" MD5="52DBFE203AA894B2DBE2FD5A1F345C23" NationalName="Y" />
  <ITEM PID="2024" File="c:\windows\svchost.exe" CheckResult="-1" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="0"  CmdLine="C:\Windows\svchost.exe" Size="36352" Attr="rSAh" CreateDate="24.08.2001 20:00:00" ChangeDate="24.08.2001 20:00:00" MD5="9E3C13B6556D5636B745D3E466D47467" Vendor="Microsoft Corporation" Product="Microsoft® Windows® Operating System" OFN="svchost.exe" />
  <ITEM PID="948" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Õîñò-ïðîöåññ äëÿ ñëóæá Windows" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Hidden="0"  CmdLine="C:\Windows\System32\svchost.exe -k secsvcs" Size="20992" Attr="rsAh" CreateDate="14.07.2009 01:19:28" ChangeDate="14.07.2009 03:14:41" MD5="54A47F6B5E09A77E61649109C6A08866" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="svchost.exe.mui" />
  <ITEM PID="5176" File="c:\program files\windows media player\wmpnetwk.exe" CheckResult="0" Descr="Ñëóæáà îáùèõ ñåòåâûõ ðåñóðñîâ ïðîèãðûâàòåëÿ Windows Media" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò (Microsoft Corp.). Âñå ïðàâà çàùèùåíû." Hidden="0"  CmdLine="&quot;C:\Program Files\Windows Media Player\wmpnetwk.exe&quot;" Size="1121280" Attr="rsAh" CreateDate="14.07.2009 02:09:32" ChangeDate="14.07.2009 03:14:47" MD5="77FBD400984CF72BA0FC4B3489D65F74" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="WMPNetwk.exe.mui" />
 </PROCESS>
 <DLL>
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b0b8554c05f194f546a8ed531320760b\mscorlib.ni.dll" CheckResult="-1"  Descr="Microsoft Common Language Runtime Class Library"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044,5232" Hidden="0" Size="11490816" Attr="rsAh" CreateDate="11.01.2013 10:01:38" ChangeDate="11.01.2013 10:01:42" MD5="2B0F70547A3E310DB6144DA9D6C07776" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="mscorlib.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c54750e64ba10d0fb7b6a636fb3695ca\System.ni.dll" CheckResult="-1"  Descr=".NET Framework"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044,5232" Hidden="0" Size="7974400" Attr="rsAh" CreateDate="11.01.2013 10:03:40" ChangeDate="11.01.2013 10:03:41" MD5="56892E1DA69ABAF325C4B83CF5CCC53A" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="System.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\82a4c4666ad83c3a375210247e69646b\WindowsBase.ni.dll" CheckResult="-1"  Descr="WindowsBase.dll"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044,5232" Hidden="0" Size="3325952" Attr="rsAh" CreateDate="11.01.2013 10:08:01" ChangeDate="11.01.2013 10:08:01" MD5="F37CC8B9B50AD9009AA054F79C093A1F" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="WindowsBase.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\549690bfac66934b7c7fd5cf8b120b7c\PresentationCore.ni.dll" CheckResult="-1"  Descr="PresentationCore.dll"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044,5232" Hidden="0" Size="12218880" Attr="rsAh" CreateDate="11.01.2013 10:11:36" ChangeDate="11.01.2013 10:11:38" MD5="40B061D011F32073524624E6BB61C301" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="PresentationCore.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\36b839247bd1d22a7fd014a74abe9729\PresentationFramework.ni.dll" CheckResult="-1"  Descr="PresentationFramework.dll"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044" Hidden="0" Size="14325760" Attr="rsAh" CreateDate="11.01.2013 10:17:59" ChangeDate="11.01.2013 10:18:04" MD5="645C6F5BA45F6615CCB8878F375582F9" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="PresentationFramework.dll" />
  <ITEM File="C:\Windows\8 Skin Pack\Aura\ru-RU\Aura.resources.dll" CheckResult="-1"  Descr="Aura"  LegalCopyright="Copyright © Stealth 2011"  UsedBy="3044" Hidden="0" Size="5632" Attr="rsAh" CreateDate="12.04.2011 15:06:30" ChangeDate="12.04.2011 15:06:30" MD5="DC871DEC9261DAC23C0C0031C31449F1" Vendor="Stealth Software" Product="Aura" OFN="Aura.resources.dll" />
  <ITEM File="C:\Windows\8 Skin Pack\Aura\Nini.dll" CheckResult="-1"  Descr="Nini for .NET Framework 2.0"  LegalCopyright="Copyright (c) 2006 Brent R. Matzelle. All Rights Reserved."  UsedBy="3044" Hidden="0" Size="69632" Attr="rsAh" CreateDate="22.03.2006 22:12:52" ChangeDate="22.03.2006 22:12:52" MD5="B56F954A761998C5C79176FE34830B9D" Vendor="Brent R. Matzelle" Product="Nini" OFN="Nini.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e2ee5d77ebe0bd025e7a7a317a43d677\System.Drawing.ni.dll" CheckResult="-1"  Descr=".NET Framework"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044" Hidden="0" Size="1592832" Attr="rsAh" CreateDate="11.01.2013 10:12:50" ChangeDate="11.01.2013 10:12:50" MD5="2A979B56AD277879CB4F25D25E531D79" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="System.Drawing.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c490a630d8595c864a445449c264775b\PresentationFramework.Classic.ni.dll" CheckResult="-1"  Descr="PresentationFramework.Classic.dll"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044" Hidden="0" Size="224768" Attr="rsAh" CreateDate="11.01.2013 11:05:54" ChangeDate="11.01.2013 11:05:54" MD5="217D53258E3C411086D56958ED295EF4" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="PresentationFramework.Classic.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\10aba2c167cc1119b80159fd9ac71ca8\System.Xml.ni.dll" CheckResult="-1"  Descr=".NET Framework"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044,5232" Hidden="0" Size="5453312" Attr="rsAh" CreateDate="11.01.2013 10:04:54" ChangeDate="11.01.2013 10:04:56" MD5="715770992D98E92095F5D7510311407C" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="System.Xml.dll" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\c6fb88c8055653672314c29ca4b78a7e\System.Windows.Forms.ni.dll" CheckResult="-1"  Descr=".NET Framework"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="3044" Hidden="0" Size="12433920" Attr="rsAh" CreateDate="11.01.2013 10:14:05" ChangeDate="11.01.2013 10:14:07" MD5="C3102EE5F4B80457EA1FB69EB453A73D" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="System.Windows.Forms.dll" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\avengine.dll.7b31486002da3dcc1d2fbe980a49667b" CheckResult="-1"  Descr="AV engine loader"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="425344" Attr="rsAh" CreateDate="19.09.2012 15:42:31" ChangeDate="19.09.2012 15:42:27" MD5="7B31486002DA3DCC1D2FBE980A49667B" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus Engine" OFN="avengine.dll" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\kavbase.kdl.3cd596e244611c75a6e7aaa354cfe616" CheckResult="-1"  Descr="AV engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="491392" Attr="rsAh" CreateDate="28.08.2012 14:32:09" ChangeDate="28.08.2012 14:29:53" MD5="3CD596E244611C75A6E7AAA354CFE616" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus engine" OFN="kavbase.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\klavemu.kdl.0030baed4db4862a4f4d01fc567d0595" CheckResult="-1"  Descr="Heuristics engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="1213440" Attr="rsAh" CreateDate="19.09.2012 15:42:32" ChangeDate="19.09.2012 15:42:28" MD5="0030BAED4DB4862A4F4D01FC567D0595" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="klavemu.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\kjim.kdl.5970398bad929b14b4f1a0708d9baf62" CheckResult="-1"  Descr="Script Heuristics Engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="262144" Attr="rsAh" CreateDate="28.08.2012 14:32:10" ChangeDate="28.08.2012 14:31:37" MD5="5970398BAD929B14B4F1A0708D9BAF62" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="kjim.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\mark.kdl.34e568d69ad5e0fd28e50af0362e1e1c" CheckResult="-1"  Descr="Anti-Rootkit Engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="147968" Attr="rsAh" CreateDate="28.08.2012 14:32:10" ChangeDate="28.08.2012 14:31:37" MD5="34E568D69AD5E0FD28E50AF0362E1E1C" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="mark.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\qscan.kdl.bbbfaecea5cdf559e87e6b95ea3a79a0" CheckResult="-1"  Descr="Initial Scan Engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="440832" Attr="rsAh" CreateDate="28.08.2012 14:32:11" ChangeDate="28.08.2012 14:31:38" MD5="BBBFAECEA5CDF559E87E6B95EA3A79A0" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="qscan.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\pbs.kdl.cdd13a8dc4f2e104e61559b6396c3444" CheckResult="-1"  Descr="Extensional Scan Engine"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="369664" Attr="rsAh" CreateDate="28.08.2012 14:32:11" ChangeDate="28.08.2012 14:31:37" MD5="CDD13A8DC4F2E104E61559B6396C3444" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="pbs.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\arkmon.kdl.54eb73d75dbbe43dc580590234954e2f" CheckResult="-1"  Descr="Anti-Rootkit Monitor"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="38400" Attr="rsAh" CreateDate="28.08.2012 14:33:11" ChangeDate="28.08.2012 14:31:37" MD5="54EB73D75DBBE43DC580590234954E2F" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="arkmon.sys" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\kavsys.kdl.2b42a13480c03637d93eecbc6447f463" CheckResult="-1"  Descr="Set of system interfaces"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="176640" Attr="rsAh" CreateDate="28.08.2012 14:33:11" ChangeDate="28.08.2012 14:31:38" MD5="2B42A13480C03637D93EECBC6447F463" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="kavsys.kdl" />
  <ITEM File="C:\ProgramData\Kaspersky Lab\AVP11\Bases\Cache\bsshlp.kdl.9131877fd450e942230ee73d2d861579" CheckResult="-1"  Descr="BSS Helper Library"  LegalCopyright="© 2012 Kaspersky Lab ZAO. All Rights Reserved."  UsedBy="1768" Hidden="0" Size="431104" Attr="rsAh" CreateDate="28.08.2012 14:33:31" ChangeDate="28.08.2012 14:33:30" MD5="9131877FD450E942230EE73D2D861579" Vendor="Kaspersky Lab ZAO" Product="Kaspersky Anti-Virus" OFN="bsshlp.kdl" />
  <ITEM File="C:\Windows\system32\EXPLORERFRAME.dll" CheckResult="-1"  Descr="ExplorerFrame"  LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò (Microsoft Corp.) Âñå ïðàâà çàùèùåíû."  UsedBy="2420" Hidden="0" Size="1495040" Attr="rsAh" CreateDate="21.10.2012 10:57:33" ChangeDate="26.06.2010 07:14:29" MD5="8249BA6AC7B786B09D9DE9A1E074E401" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="ExplorerFrame.dll.mui" />
  <ITEM File="C:\Windows\system32\authui.dll" CheckResult="-1"  Descr="Èíòåðôåéñ ïðîâåðêè ïîäëèííîñòè"  LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû."  UsedBy="2420" Hidden="0" Size="1791488" Attr="rsAh" CreateDate="21.10.2012 10:56:15" ChangeDate="14.07.2009 03:14:57" MD5="39EE4FE9584EED106BA773EAC8DEABEA" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="AUTHUI.DLL.MUI" />
  <ITEM File="C:\Program Files\Ticno\Tabs\TicnoTabsBho120618.dll" CheckResult="-1"  Descr="BhoNew Module"  LegalCopyright="Copyright 2005"  UsedBy="2420" Hidden="0" Size="684544" Attr="rsAh" CreateDate="18.06.2012 20:35:02" ChangeDate="18.06.2012 20:35:02" MD5="86E1471E9E9E96D64A0280E6EEAA148C" Product="BhoNew Module" OFN="BhoNew.DLL" />
  <ITEM File="C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll" CheckResult="-1"  Descr="MailRuSputnik Module"  LegalCopyright="Copyright © 2005 - 2011"  UsedBy="2420" Hidden="0" Size="1812072" Attr="rsAh" CreateDate="20.09.2012 15:14:34" ChangeDate="20.09.2012 15:14:34" MD5="13338F7A9F2354F7BCE9B1981EAD81DD" Vendor="@Mail.Ru" Product="MailRuSputnik Module" OFN="MailRuSputnik.DLL" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Local\Ticno\Multibar\plugins\games\games.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="2876" Hidden="0" Size="237056" Attr="rsAh" CreateDate="20.10.2012 05:01:34" ChangeDate="16.05.2012 12:32:58" MD5="4B3082D68A77A8CA06BE18182A76D9DC" NationalName="Y" />
  <ITEM File="C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\782689ccb5695c4e2b45d50d62a94f03\System.ServiceProcess.ni.dll" CheckResult="-1"  Descr=".NET Framework"  LegalCopyright="© Microsoft Corporation.  All rights reserved."  UsedBy="5232" Hidden="0" Size="212992" Attr="rsAh" CreateDate="11.01.2013 10:58:55" ChangeDate="11.01.2013 10:58:55" MD5="FECF6EAF52D71B5A8B21FD61CF04F067" Vendor="Microsoft Corporation" Product="Microsoft® .NET Framework" OFN="System.ServiceProcess.dll" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Local\Skymonk2\browser.dll" CheckResult="-1"  Descr=""  LegalCopyright=""  UsedBy="3884" Hidden="0" Size="19875984" Attr="rsAh" CreateDate="20.09.2012 15:14:00" ChangeDate="03.01.2012 13:43:22" MD5="688760528A7110AFC4AFC1CBE5CD3F26" NationalName="Y" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Local\Skymonk2\icudt.dll" CheckResult="-1"  Descr="ICU Data DLL"  LegalCopyright=" Copyright (C) 2011, International Business Machines Corporation and others. All Rights Reserved. "  UsedBy="3884" Hidden="0" Size="4571136" Attr="rsAh" CreateDate="20.09.2012 15:14:00" ChangeDate="20.09.2012 15:14:00" MD5="08C60C509300E35F56ACFB4306B6C7B1" Vendor="The ICU Project" Product="International Components for Unicode" OFN="icudt46.dll" NationalName="Y" />
  <ITEM File="C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7B7145E8-7870-4791-8AD7-17F5B434D02E}\mpengine.dll" CheckResult="-1"  Descr="Microsoft Malware Protection Engine"  LegalCopyright="© Microsoft Corporation. All rights reserved."  UsedBy="948" Hidden="0" Size="6812136" Attr="rsAh" CreateDate="11.01.2013 14:03:00" ChangeDate="19.11.2012 01:04:10" MD5="11F06C27DAD83CD5E907D664CA591805" Vendor="Microsoft Corporation" Product="Microsoft Malware Protection" OFN="mpengine.dll" />
  <ITEM File="\\?\C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv01.key" CheckResult="-1"  Descr="Individualized Black Box DLL"  LegalCopyright="© Microsoft Corporation. All rights reserved."  UsedBy="5176" Hidden="0" Size="1488656" Attr="rSAH" CreateDate="28.09.2012 17:08:35" ChangeDate="26.09.2012 14:27:39" MD5="5E5921C6898F6D01C5AD047D0F01713E" Vendor="Microsoft Corporation" Product="Microsoft® DRM" OFN="Individualized Black Box DLL" />
 </DLL>
 <KERNELOBJ>
  <ITEM File="C:\Windows\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="93EED000" MemSize="009000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\Windows\System32\Drivers\dump_dumpata.sys" CheckResult="-1" Base="93EE2000" MemSize="00B000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\Windows\System32\Drivers\dump_dumpfve.sys" CheckResult="-1" Base="93EF6000" MemSize="011000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\Windows\System32\Drivers\spao.sys" CheckResult="-1" Base="83ECA000" MemSize="101000" Descr="" LegalCopyright=""  />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys" CheckResult="-1" Base="A8B75000" MemSize="001000" Descr="TuneUp Utilities Driver" LegalCopyright="Copyright © TuneUp Software GmbH" Size="10088" Attr="rsAh" CreateDate="18.09.2012 15:02:02" ChangeDate="18.09.2012 15:02:02" MD5="94C4CD2D19B8C4137A46261F229FEC24" Vendor="TuneUp Software" Product="TuneUp Utilities" />
 </KERNELOBJ>
 <Service>
  <ITEM File="C:\Windows\svchost.exe" Name="PowerManager" CheckResult="-1" Type="16" State="4" Size="36352" Attr="rSAh" CreateDate="24.08.2001 20:00:00" ChangeDate="24.08.2001 20:00:00" MD5="9E3C13B6556D5636B745D3E466D47467" Vendor="Microsoft Corporation" Product="Microsoft® Windows® Operating System" OFN="svchost.exe"  />
  <ITEM File="C:\Program Files\Ticno\Indexator\SearchService.exe" Name="TicnoIndexator" CheckResult="-1" Type="272" State="4" Size="517632" Attr="rsAh" CreateDate="10.05.2012 12:18:38" ChangeDate="10.05.2012 12:18:38" MD5="4E74CCB023265BDA0936F264EFBF43D7"  />
  <ITEM File="C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe" Name="Guard.Mail.ru" CheckResult="-1" Type="16" State="1" Size="2259560" Attr="rsAh" CreateDate="20.09.2012 15:14:42" ChangeDate="17.11.2012 10:01:10" MD5="9D784A0C003D34AF9CE2F0001D28725F" Product="GuardMailRu Module" OFN="GuardMailRu.exe"  />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe" Name="TuneUp.UtilitiesSvc" CheckResult="-1" Type="16" State="1" Size="1699168" Attr="rsAh" CreateDate="31.10.2012 14:24:06" ChangeDate="31.10.2012 14:24:06" MD5="A378A6616C2735EF3F444450F3B987CB" Vendor="TuneUp Software" Product="TuneUp Utilities 2013"  />
 </Service>
 <Drivers>
  <ITEM File="C:\Windows\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="722416" Attr="rsAh" CreateDate="05.01.2010 08:27:54" ChangeDate="05.01.2010 08:27:54" MD5=""  />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys" Name="TuneUpUtilitiesDrv" CheckResult="-1" Type="1" State="4" Size="10088" Attr="rsAh" CreateDate="18.09.2012 15:02:02" ChangeDate="18.09.2012 15:02:02" MD5="94C4CD2D19B8C4137A46261F229FEC24" Vendor="TuneUp Software" Product="TuneUp Utilities"  />
  <ITEM File="C:\Windows\system32\drivers\RTKVHDA.sys" Name="IntcAzAudAddService" CheckResult="-1" Type="1" State="1" Size="2361952" Attr="RsAh" CreateDate="05.01.2010 07:03:56" ChangeDate="23.05.2009 02:03:40" MD5="8B27C21412AE4404EB0ACFE1D98579EC" Vendor="Realtek Semiconductor Corp." Product="Realtek(r) High Definition Audio Function Driver" OFN="RtkHDAud.sys"  />
  <ITEM File="C:\Windows\system32\DRIVERS\m5287.sys" Name="m5287" CheckResult="-1" Type="1" State="1" Size="104320" Attr="RsAh" CreateDate="05.01.2010 07:14:11" ChangeDate="20.07.2006 20:47:12" MD5="EA5D45CB664E7EC7E0906FB670334C45" Vendor="ULi Electronics Inc." Product="ULi SATA Controller Driver"  />
  <ITEM File="C:\Windows\system32\DRIVERS\m5288.sys" Name="m5288" CheckResult="-1" Type="1" State="1" Size="211072" Attr="RsAh" CreateDate="05.01.2010 07:14:11" ChangeDate="19.07.2006 19:48:14" MD5="C0B201B3C26CD187AAA797577D4B48FC" Vendor="ULi Electronics Inc." Product="ULi SATA Controller Driver"  />
 </Drivers>
 <AUTORUN>
  <ITEM File=".exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\RunOnce" X3="Application Restart #0" />
  <ITEM File="C:\85c54489fb0424024df83f3875c6\DW\DW20.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup" X3="EventMessageFile" />
  <ITEM File="C:\Program Files\AIMP2\AIMP2.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="1445376" Attr="rsAh" CreateDate="20.10.2009 18:16:10" ChangeDate="20.10.2009 18:16:10" MD5="558F6B297893345790E2C276F090E908" Vendor="AIMP DevTeam" Product="AIMP2" X1="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AIMP2.lnk" X3="" />
  <ITEM File="C:\Program Files\Mozilla Firefox\firefox.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="7686768" Attr="rsAh" CreateDate="05.01.2010 08:49:25" ChangeDate="15.11.2007 20:49:55" MD5="D4CDA7E81085FD5E3B3595F490002060" Vendor="Mozilla Corporation" Product="Firefox" OFN="firefox.exe" X1="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk" X3="" />
  <ITEM File="C:\Program Files\Oracle\VirtualBox\VirtualBox.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="7181224" Attr="rsAh" CreateDate="19.12.2012 15:36:44" ChangeDate="19.12.2012 15:36:44" MD5="5DEDAFAEF73FCBB02669E8753BDE0721" Vendor="Oracle Corporation" Product="Oracle VM VirtualBox" OFN="VirtualBox.exe" X1="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk" X3="" />
  <ITEM File="C:\Program Files\Svyaznoy Modem\ModemListener.exe" CheckResult="-1" Enabled="1" Type="REG" Size="98304" Attr="rsAh" CreateDate="20.03.2012 21:02:10" ChangeDate="31.03.2011 11:16:24" MD5="C5356FCE3BC8E685DE0C111D22FA85DA" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="ModemListener" />
  <ITEM File="C:\Program Files\Ticno\Multibar\multibar.exe" CheckResult="-1" Enabled="1" Type="REG" Size="510976" Attr="rsAh" CreateDate="26.01.2012 01:38:20" ChangeDate="26.01.2012 01:38:20" MD5="F9302AE9695DA98457E9E86768796F8A" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="multibar.exe" />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\DseShExt-x86.dll" CheckResult="-1" Enabled="1" Type="REG" Size="25952" Attr="rsAh" CreateDate="31.10.2012 14:24:02" ChangeDate="31.10.2012 14:24:02" MD5="9058B77F90DBDAD74536AE3B1DF5855F" Vendor="TuneUp Software" Product="TuneUp Utilities 2013" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{4838CD50-7E5D-4811-9B17-C47A85539F28}" />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\SDShelEx-win32.dll" CheckResult="-1" Enabled="1" Type="REG" Size="30048" Attr="rsAh" CreateDate="31.10.2012 14:24:02" ChangeDate="31.10.2012 14:24:02" MD5="60615B9EFA53D06DA7259D661B96A3EA" Vendor="TuneUp Software" Product="TuneUp Utilities 2013" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X3="{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe" CheckResult="-1" Enabled="-1" Type="REG" Size="1699168" Attr="rsAh" CreateDate="31.10.2012 14:24:06" ChangeDate="31.10.2012 14:24:06" MD5="A378A6616C2735EF3F444450F3B987CB" Vendor="TuneUp Software" Product="TuneUp Utilities 2013" X1="HKEY_LOCAL_MACHINE" X2="SYSTEM\CurrentControlSet\Services\Eventlog\TuneUp\TuneUp.UtilitiesSvc" X3="EventMessageFile" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Local\Skymonk2\skymonk2.exe" CheckResult="-1" Enabled="1" Type="REG" Size="489616" Attr="rsAh" CreateDate="26.09.2012 13:43:36" ChangeDate="11.01.2013 13:45:22" MD5="D30F7E0F7FBAE3B69A2E3AEB220E52BF" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Skymonk2" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\7C.exe" CheckResult="-1" Enabled="1" Type="REG" Size="302912" Attr="rsAh" CreateDate="06.01.2013 06:13:43" ChangeDate="06.01.2013 06:13:43" MD5="B2DEF58915E5A846921A7D3A895ECB56" Vendor="Avira GmbH" Product="AntiVir Desktop" OFN="avscan.exe" NationalName="Y" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="PIg" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\7C.exe" CheckResult="-1" Enabled="1" Type="REG" Size="302912" Attr="rsAh" CreateDate="06.01.2013 06:13:43" ChangeDate="06.01.2013 06:13:43" MD5="B2DEF58915E5A846921A7D3A895ECB56" Vendor="Avira GmbH" Product="AntiVir Desktop" OFN="avscan.exe" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" X3="PIg" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\BE86.exe" CheckResult="-1" Enabled="1" Type="REG" Size="302912" Attr="rsAh" CreateDate="11.01.2013 14:09:54" ChangeDate="11.01.2013 14:09:54" MD5="B2DEF58915E5A846921A7D3A895ECB56" Vendor="Avira GmbH" Product="AntiVir Desktop" OFN="avscan.exe" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="PIg" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk" CheckResult="-1" Enabled="1" Type="FILE" Size="290" Attr="rsAh" CreateDate="05.01.2010 08:31:59" ChangeDate="14.07.2009 06:37:42" MD5="9A79C9E1AD63ED2E7932536570775B9F" NationalName="Y" X1="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk" X3="" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk" CheckResult="-1" Enabled="1" Type="FILE" Size="272" Attr="rsAh" CreateDate="05.01.2010 08:31:59" ChangeDate="14.07.2009 06:37:42" MD5="E14F6EF5E8DC4C628FE28AC893E9309D" NationalName="Y" X1="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\" X2="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk" X3="" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Ulvavu.exe" CheckResult="-1" Enabled="1" Type="REG" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Ulvavu" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Vlvavv.exe" CheckResult="-1" Enabled="1" Type="REG" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Vlvavv" />
  <ITEM File="C:\Users\Àäìèíèñòðàòîð\AppData\Roaming\Xlvavx.exe" CheckResult="-1" Enabled="1" Type="REG" NationalName="Y" X1="HKEY_CURRENT_USER" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="Xlvavx" />
  <ITEM File="C:\Windows\8 Skin Pack\Aura\Aura.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="471040" Attr="rsAh" CreateDate="12.04.2011 15:14:00" ChangeDate="12.04.2011 15:14:00" MD5="B13404D4770A8590409A22288F47AF3E" Vendor="Stealth Software" Product="Aura" OFN="Aura.exe" X1="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\" X2="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aura.lnk" X3="" />
  <ITEM File="C:\Windows\system32\psxss.exe" CheckResult="-1" Enabled="-1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="System\CurrentControlSet\Control\Session Manager\SubSystems" X3="Posix" />
  <ITEM File="\Synaptics\SynTP\SynTPEnh.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="SynTPEnh" />
  <ITEM File="progman.exe" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="shell" />
  <ITEM File="vgafix.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fixedfon.fon" />
  <ITEM File="vgaoem.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="oemfonts.fon" />
  <ITEM File="vgasys.fon" CheckResult="-1" Enabled="1" Type="REG"  X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows NT\CurrentVersion\WOW\boot" X3="fonts.fon" />
 </AUTORUN>
 <BHO>
  <ITEM File="C:\Program Files\Ticno\Tabs\TicnoTabsBho120618.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}" Descr="BhoNew Module" LegalCopyright="Copyright 2005" Size="684544" Attr="rsAh" CreateDate="18.06.2012 20:35:02" ChangeDate="18.06.2012 20:35:02" MD5="86E1471E9E9E96D64A0280E6EEAA148C" Product="BhoNew Module" OFN="BhoNew.DLL"  />
  <ITEM File="C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{8984B388-A5BB-4DF7-B274-77B879E179DB}" Descr="MailRuSputnik Module" LegalCopyright="Copyright © 2005 - 2011" Size="1812072" Attr="rsAh" CreateDate="20.09.2012 15:14:34" ChangeDate="20.09.2012 15:14:34" MD5="13338F7A9F2354F7BCE9B1981EAD81DD" Vendor="@Mail.Ru" Product="MailRuSputnik Module" OFN="MailRuSputnik.DLL"  />
  <ITEM File="C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll" CheckResult="-1" Enabled="1" BHOType="2" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" CLSID="{09900DE8-1DCA-443F-9243-26FF581438AF}" Descr="MailRuSputnik Module" LegalCopyright="Copyright © 2005 - 2011" Size="1812072" Attr="rsAh" CreateDate="20.09.2012 15:14:34" ChangeDate="20.09.2012 15:14:34" MD5="13338F7A9F2354F7BCE9B1981EAD81DD" Vendor="@Mail.Ru" Product="MailRuSputnik Module" OFN="MailRuSputnik.DLL"  />
  <ITEM File="C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll" CheckResult="-1" Enabled="1" BHOType="4" RegKey="HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks" CLSID="{09900DE8-1DCA-443F-9243-26FF581438AF}" Descr="MailRuSputnik Module" LegalCopyright="Copyright © 2005 - 2011" Size="1812072" Attr="rsAh" CreateDate="20.09.2012 15:14:34" ChangeDate="20.09.2012 15:14:34" MD5="13338F7A9F2354F7BCE9B1981EAD81DD" Vendor="@Mail.Ru" Product="MailRuSputnik Module" OFN="MailRuSputnik.DLL"  />
 </BHO>
 <ExplorerExt>
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="Synaptics Control Panel" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{2F603045-309F-11CF-9774-0020AFD0CFF6}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="HashTab Context Menu" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{B1883831-F0D8-4453-8245-EEAAD866DD6E}" Descr="" LegalCopyright=""   />
  <ITEM File="" CheckResult="-1" Enabled="1" ExtType="1" ExtName="WebCheck" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" Descr="" LegalCopyright=""   />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\SDShelEx-win32.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="TuneUp Shredder Shell Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" Descr="TuneUp Shredder Shell Extension" LegalCopyright="" Size="30048" Attr="rsAh" CreateDate="31.10.2012 14:24:02" ChangeDate="31.10.2012 14:24:02" MD5="60615B9EFA53D06DA7259D661B96A3EA" Vendor="TuneUp Software" Product="TuneUp Utilities 2013"  />
  <ITEM File="C:\Program Files\TuneUp Utilities 2013\DseShExt-x86.dll" CheckResult="-1" Enabled="1" ExtType="1" ExtName="TuneUp Disk Space Explorer Shell Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{4838CD50-7E5D-4811-9B17-C47A85539F28}" Descr="TuneUp Disk Space Explorer Shell Extension" LegalCopyright="" Size="25952" Attr="rsAh" CreateDate="31.10.2012 14:24:02" ChangeDate="31.10.2012 14:24:02" MD5="9058B77F90DBDAD74536AE3B1DF5855F" Vendor="TuneUp Software" Product="TuneUp Utilities 2013"  />
 </ExplorerExt>
 <PrintEXT>
 </PrintEXT>
 <TaskScheduler>
 </TaskScheduler>
 <SPI>
  <ITEM File="C:\Windows\system32\NLAapi.dll" CheckResult="-1" SPIType="1" SPINaim="@%SystemRoot%\system32\nlasvc.dll,-1000" Descr="Network Location Awareness 2" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="51712" Attr="rsAh" CreateDate="14.07.2009 01:53:54" ChangeDate="14.07.2009 03:16:03" MD5="045DB4EAB4FBD23210E85ECC3F464A2E" Vendor="Microsoft Corporation" Product="Microsoft® Windows® Operating System" OFN="nlaapi.dll"  />
  <ITEM File="C:\Windows\System32\mswsock.dll" CheckResult="-1" SPIType="1" SPINaim="@%SystemRoot%\system32\wshtcpip.dll,-60103" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\System32\winrnr.dll" CheckResult="-1" SPIType="1" SPINaim="NTDS" Descr="LDAP RnR Provider DLL" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="20992" Attr="rsAh" CreateDate="14.07.2009 01:37:57" ChangeDate="14.07.2009 03:16:19" MD5="5DF5D8CFD9B9573FA3B2C89D9061A240" Vendor="Microsoft Corporation" Product="Microsoft® Windows® Operating System" OFN="winrnr"  />
  <ITEM File="C:\Windows\system32\napinsp.dll" CheckResult="-1" SPIType="1" SPINaim="@%SystemRoot%\system32\napinsp.dll,-1000" Descr="Ïîñòàâùèê îáîëî÷êè ñîâìåñòèìîñòè äëÿ èìåí ýëåêòðîííîé ïî÷òû" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="52224" Attr="rsAh" CreateDate="14.07.2009 01:54:55" ChangeDate="14.07.2009 03:16:02" MD5="0B7E85364CB878E2AD531DB7B601A9E5" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="napinsp.dll.mui"  />
  <ITEM File="C:\Windows\system32\pnrpnsp.dll" CheckResult="-1" SPIType="1" SPINaim="@%SystemRoot%\system32\pnrpnsp.dll,-1000" Descr="Ïîñòàâùèê ïðîñòðàíñòâà èìåí PNRP" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="65024" Attr="rsAh" CreateDate="14.07.2009 01:55:50" ChangeDate="14.07.2009 03:16:12" MD5="5CF640EDDB1E40A5AB1BB743BCDEC610" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="pnrpnsp.dll.mui"  />
  <ITEM File="C:\Windows\system32\pnrpnsp.dll" CheckResult="-1" SPIType="1" SPINaim="@%SystemRoot%\system32\pnrpnsp.dll,-1001" Descr="Ïîñòàâùèê ïðîñòðàíñòâà èìåí PNRP" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="65024" Attr="rsAh" CreateDate="14.07.2009 01:55:50" ChangeDate="14.07.2009 03:16:12" MD5="5CF640EDDB1E40A5AB1BB743BCDEC610" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="pnrpnsp.dll.mui"  />
  <ITEM File="C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL" CheckResult="-1" SPIType="1" SPINaim="WindowsLive NSP" Descr="Microsoft® Windows Live ID Namespace Provider" LegalCopyright="© Microsoft Corporation.  All rights reserved." Size="134528" Attr="rsAh" CreateDate="18.08.2009 10:29:22" ChangeDate="18.08.2009 10:29:22" MD5="835BFF67EBD89BCE0B13460B2A56C53E" Vendor="Microsoft Corporation" Product="Microsoft® Windows Live ID" OFN="WlidNSP.dll"  />
  <ITEM File="C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL" CheckResult="-1" SPIType="1" SPINaim="WindowsLive Local NSP" Descr="Microsoft® Windows Live ID Namespace Provider" LegalCopyright="© Microsoft Corporation.  All rights reserved." Size="134528" Attr="rsAh" CreateDate="18.08.2009 10:29:22" ChangeDate="18.08.2009 10:29:22" MD5="835BFF67EBD89BCE0B13460B2A56C53E" Vendor="Microsoft Corporation" Product="Microsoft® Windows Live ID" OFN="WlidNSP.dll"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60100" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60101" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60102" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wship6.dll,-60100" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wship6.dll,-60101" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wship6.dll,-60102" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshqos.dll,-100" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshqos.dll,-101" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshqos.dll,-102" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="@%SystemRoot%\System32\wshqos.dll,-103" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Pgm (RDM)" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD Pgm (Stream)" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{20C92341-5047-42B7-BFC9-0E98FEBA47BC}] SEQPACKET 13" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{20C92341-5047-42B7-BFC9-0E98FEBA47BC}] DATAGRAM 13" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{00F423E0-0CA5-46FA-97E0-4EFB6F994FCF}] SEQPACKET 5" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{00F423E0-0CA5-46FA-97E0-4EFB6F994FCF}] DATAGRAM 5" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{08E98E39-0B93-4F7D-AF14-6A7D5D92C956}] SEQPACKET 0" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{08E98E39-0B93-4F7D-AF14-6A7D5D92C956}] DATAGRAM 0" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6AC12175-ABE5-4F30-8F4D-A70C929395FC}] SEQPACKET 10" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6AC12175-ABE5-4F30-8F4D-A70C929395FC}] DATAGRAM 10" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{28F60137-5C98-42B8-A386-A91141B5214C}] SEQPACKET 9" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{28F60137-5C98-42B8-A386-A91141B5214C}] DATAGRAM 9" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3C4FB383-AB4D-4D18-8D92-4221B3706568}] SEQPACKET 6" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3C4FB383-AB4D-4D18-8D92-4221B3706568}] DATAGRAM 6" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0A922705-E354-46CE-A581-B67B8C417209}] SEQPACKET 8" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0A922705-E354-46CE-A581-B67B8C417209}] DATAGRAM 8" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EC559981-5E6C-4F6B-9B37-7208D7A0114B}] SEQPACKET 4" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EC559981-5E6C-4F6B-9B37-7208D7A0114B}] DATAGRAM 4" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E7F218A7-AF18-4550-A167-F98E693E1FB2}] SEQPACKET 2" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E7F218A7-AF18-4550-A167-F98E693E1FB2}] DATAGRAM 2" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A7D9A1B6-5F43-4620-ABE2-43114B5F46DA}] SEQPACKET 12" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A7D9A1B6-5F43-4620-ABE2-43114B5F46DA}] DATAGRAM 12" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{28F60137-5C98-42B8-A386-A91141B5214C}] SEQPACKET 7" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{28F60137-5C98-42B8-A386-A91141B5214C}] DATAGRAM 7" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC559981-5E6C-4F6B-9B37-7208D7A0114B}] SEQPACKET 3" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC559981-5E6C-4F6B-9B37-7208D7A0114B}] DATAGRAM 3" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7F218A7-AF18-4550-A167-F98E693E1FB2}] SEQPACKET 1" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7F218A7-AF18-4550-A167-F98E693E1FB2}] DATAGRAM 1" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{A7D9A1B6-5F43-4620-ABE2-43114B5F46DA}] SEQPACKET 11" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
  <ITEM File="C:\Windows\system32\mswsock.dll" CheckResult="-1" SPIType="3" SPINaim="MSAFD NetBIOS [\Device\NetBT_Tcpip_{A7D9A1B6-5F43-4620-ABE2-43114B5F46DA}] DATAGRAM 11" Descr="Ðàñøèðåíèå ïîñòàâùèêà ñëóæáû API Microsoft Windows Sockets 2.0" LegalCopyright="© Êîðïîðàöèÿ Ìàéêðîñîôò. Âñå ïðàâà çàùèùåíû." Size="232448" Attr="rsAh" CreateDate="14.07.2009 01:12:34" ChangeDate="14.07.2009 03:15:51" MD5="11A41F17527ED75D6B758FDD7F4FD00D" Vendor="Microsoft Corporation" Product="Îïåðàöèîííàÿ ñèñòåìà Microsoft® Windows®" OFN="mswsock.dll.mui"  />
 </SPI>
 <DPF>
 </DPF>
 <CPL>
  <ITEM File="C:\Windows\system32\RTSndMgr.cpl" CheckResult="-1" Enabled="1" Descr="Realtek HD Audio Control Panel" LegalCopyright="Copyright (c) 2004 Realtek Semiconductor Corp." Size="551456" Attr="RsAh" CreateDate="05.01.2010 07:22:06" ChangeDate="23.05.2009 00:22:48" MD5="767D38CC5C14A73C133FA4DB212AECAF" Vendor="Realtek Semiconductor Corp." Product="Realtek HD Audio Sound Effect Manager" OFN="RTSndMgr.cpl"  />
 </CPL>
 <ActiveSetup>
 </ActiveSetup>
 <HOSTS>
 </HOSTS>
 <ProtocolExt>
 </ProtocolExt>
 <SuspFiles>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys" VirType="4" Descr="Ïåðåõâàò÷èê KernelMode" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF" />
  <ITEM File="C:\Windows\svchost.exe" VirType="3" Descr=" ÝÏÑ: ïîäîçðåíèå íà Ôàéë ñ ïîäîçðèòåëüíûì èìåíåì (âûñîêàÿ ñòåïåíü âåðîÿòíîñòè)" Size="36352" Attr="rSAh" CreateDate="24.08.2001 20:00:00" ChangeDate="24.08.2001 20:00:00" MD5="9E3C13B6556D5636B745D3E466D47467" Vendor="Microsoft Corporation" Product="Microsoft® Windows® Operating System" OFN="svchost.exe" />
 </SuspFiles>
 <RK_UM>
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileA" FIndx="113" HookPtr="757D7CCC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileW" FIndx="118" HookPtr="757A8CF7" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileA" FIndx="137" HookPtr="757C28DC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileW" FIndx="144" HookPtr="757C0B3D" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileA" FIndx="863" HookPtr="757FAD31" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileW" FIndx="868" HookPtr="757AA1DB" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="LdrLoadDll" FIndx="122" HookPtr="770DF425" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtEnumerateValueKey" FIndx="282" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtQueryDirectoryFile" FIndx="387" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtResumeThread" FIndx="468" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwEnumerateValueKey" FIndx="1516" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwQueryDirectoryFile" FIndx="1620" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwResumeThread" FIndx="1701" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="GetAddrInfoW" FIndx="5" HookPtr="75C460F5" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="send" FIndx="162" HookPtr="75C4C4C8" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestA" FIndx="91" HookPtr="75E9525A" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestW" FIndx="94" HookPtr="75E6632D" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="InternetWriteFile" FIndx="191" HookPtr="75E7F6C6" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileA" FIndx="106" HookPtr="75DA0CB4" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileW" FIndx="107" HookPtr="75D5126C" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileA" FIndx="113" HookPtr="757D7CCC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileW" FIndx="118" HookPtr="757A8CF7" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileA" FIndx="137" HookPtr="757C28DC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileW" FIndx="144" HookPtr="757C0B3D" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileA" FIndx="863" HookPtr="757FAD31" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileW" FIndx="868" HookPtr="757AA1DB" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="LdrLoadDll" FIndx="122" HookPtr="770DF425" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtEnumerateValueKey" FIndx="282" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtQueryDirectoryFile" FIndx="387" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtResumeThread" FIndx="468" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwEnumerateValueKey" FIndx="1516" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwQueryDirectoryFile" FIndx="1620" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwResumeThread" FIndx="1701" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="GetAddrInfoW" FIndx="5" HookPtr="75C460F5" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="send" FIndx="162" HookPtr="75C4C4C8" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestA" FIndx="91" HookPtr="75E9525A" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestW" FIndx="94" HookPtr="75E6632D" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="InternetWriteFile" FIndx="191" HookPtr="75E7F6C6" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileA" FIndx="106" HookPtr="75DA0CB4" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileW" FIndx="107" HookPtr="75D5126C" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileA" FIndx="113" HookPtr="757D7CCC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CopyFileW" FIndx="118" HookPtr="757A8CF7" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileA" FIndx="137" HookPtr="757C28DC" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="CreateFileW" FIndx="144" HookPtr="757C0B3D" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileA" FIndx="863" HookPtr="757FAD31" HookType="2" />
  <ITEM DLL="kernel32.dll"  FNaim="MoveFileW" FIndx="868" HookPtr="757AA1DB" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="LdrLoadDll" FIndx="122" HookPtr="770DF425" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtEnumerateValueKey" FIndx="282" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtQueryDirectoryFile" FIndx="387" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="NtResumeThread" FIndx="468" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwEnumerateValueKey" FIndx="1516" HookPtr="770C4A00" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwQueryDirectoryFile" FIndx="1620" HookPtr="770C5080" HookType="2" />
  <ITEM DLL="ntdll.dll"  FNaim="ZwResumeThread" FIndx="1701" HookPtr="770C5590" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="GetAddrInfoW" FIndx="5" HookPtr="75C460F5" HookType="2" />
  <ITEM DLL="ws2_32.dll"  FNaim="send" FIndx="162" HookPtr="75C4C4C8" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestA" FIndx="91" HookPtr="75E9525A" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="HttpSendRequestW" FIndx="94" HookPtr="75E6632D" HookType="2" />
  <ITEM DLL="wininet.dll"  FNaim="InternetWriteFile" FIndx="191" HookPtr="75E7F6C6" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileA" FIndx="106" HookPtr="75DA0CB4" HookType="2" />
  <ITEM DLL="urlmon.dll"  FNaim="URLDownloadToFileW" FIndx="107" HookPtr="75D5126C" HookType="2" />
 </RK_UM>
 <IPU>
  <ITEM Code="1" X1="TermService" X2="Ñëóæáû óäàëåííûõ ðàáî÷èõ ñòîëîâ" />
  <ITEM Code="1" X1="SSDPSRV" X2="Îáíàðóæåíèå SSDP" />
  <ITEM Code="1" X1="Schedule" X2="Ïëàíèðîâùèê çàäàíèé" />
  <ITEM Code="2" />
  <ITEM Code="3" />
  <ITEM Code="5" />
  <ITEM Code="6" X1="1201" />
  <ITEM Code="6" X1="1001" />
  <ITEM Code="6" X1="1004" />
  <ITEM Code="6" X1="2201" />
  <ITEM Code="6" X1="1804" />
  <ITEM Code="8" X1="-1" />
  <ITEM Code="1" X1="TermService" X2="Ñëóæáû óäàëåííûõ ðàáî÷èõ ñòîëîâ" />
  <ITEM Code="1" X1="SSDPSRV" X2="Îáíàðóæåíèå SSDP" />
  <ITEM Code="1" X1="Schedule" X2="Ïëàíèðîâùèê çàäàíèé" />
  <ITEM Code="2" />
  <ITEM Code="3" />
  <ITEM Code="5" />
  <ITEM Code="6" X1="1201" />
  <ITEM Code="6" X1="1001" />
  <ITEM Code="6" X1="1004" />
  <ITEM Code="6" X1="2201" />
  <ITEM Code="6" X1="1804" />
  <ITEM Code="8" X1="-1" />
 </IPU>
 <RK_KM>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtAdjustPrivilegesToken" FIndx="12" HookPtr="8858ADAA" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtAlpcConnectPort" FIndx="22" HookPtr="8858CFE8" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtAlpcCreatePort" FIndx="23" HookPtr="8858D262" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtAlpcSendWaitReceivePort" FIndx="39" HookPtr="8858D4D8" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtClose" FIndx="50" HookPtr="8858B6BE" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtConnectPort" FIndx="59" HookPtr="8858C4F2" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateEvent" FIndx="64" HookPtr="8858CA3C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateFile" FIndx="66" HookPtr="8858B99A" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateMutant" FIndx="74" HookPtr="8858C922" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateNamedPipeFile" FIndx="75" HookPtr="8858A998" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreatePort" FIndx="77" HookPtr="8858C7F6" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateSection" FIndx="84" HookPtr="8858AB40" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateSemaphore" FIndx="85" HookPtr="8858CB5C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateThread" FIndx="87" HookPtr="8858B344" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateThreadEx" FIndx="88" HookPtr="8858B442" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateUserProcess" FIndx="93" HookPtr="8858D722" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtCreateWaitablePort" FIndx="94" HookPtr="8858C88C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtDebugActiveProcess" FIndx="96" HookPtr="8858E24A" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtDeviceIoControlFile" FIndx="107" HookPtr="8858BE1C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtDuplicateObject" FIndx="111" HookPtr="8858F458" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtFsControlFile" FIndx="134" HookPtr="8858BC2A" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtLoadDriver" FIndx="155" HookPtr="8858E33C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtMapViewOfSection" FIndx="168" HookPtr="8858EAA4" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenEvent" FIndx="177" HookPtr="8858CAD2" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenFile" FIndx="179" HookPtr="8858B740" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenMutant" FIndx="187" HookPtr="8858C9B2" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenProcess" FIndx="190" HookPtr="8858AFE8" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenSection" FIndx="194" HookPtr="8858E83E" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenSemaphore" FIndx="195" HookPtr="8858CBF2" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtOpenThread" FIndx="198" HookPtr="8858AED8" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtQueryDirectoryObject" FIndx="224" HookPtr="8858D7DC" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtQuerySection" FIndx="254" HookPtr="8858EDDE" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtQueueApcThread" FIndx="269" HookPtr="8858E6D0" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtReplaceKey" FIndx="292" HookPtr="88589652" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtReplyPort" FIndx="294" HookPtr="8858CF56" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtReplyWaitReceivePort" FIndx="295" HookPtr="8858CE1C" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtRequestWaitReplyPort" FIndx="299" HookPtr="8858DFE4" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtRestoreKey" FIndx="302" HookPtr="885899CA" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtResumeThread" FIndx="304" HookPtr="8858F2FA" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSaveKey" FIndx="309" HookPtr="885895EA" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSecureConnectPort" FIndx="312" HookPtr="8858C238" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSetContextThread" FIndx="316" HookPtr="8858B560" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSetInformationToken" FIndx="336" HookPtr="8858D87E" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSetSecurityObject" FIndx="347" HookPtr="8858E4DA" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSetSystemInformation" FIndx="350" HookPtr="8858EF2E" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSuspendProcess" FIndx="366" HookPtr="8858F020" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSuspendThread" FIndx="367" HookPtr="8858F15A" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtSystemDebugControl" FIndx="368" HookPtr="8858E16E" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtTerminateProcess" FIndx="370" HookPtr="8858B18E" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtTerminateThread" FIndx="371" HookPtr="8858B0E4" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtUnmapViewOfSection" FIndx="385" HookPtr="8858EC82" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
  <ITEM File="C:\Windows\system32\DRIVERS\klif.sys"  FNaim="NtWriteVirtualMemory" FIndx="399" HookPtr="8858B27A" HookType="1" CheckResult="0" Size="488536" Attr="rsAh" CreateDate="28.08.2012 08:41:46" ChangeDate="28.08.2012 08:41:47" MD5="39920D69EAEDB51757527AA54FE25216" Vendor="Kaspersky Lab" Product="Kaspersky™ Anti-Virus ®" OFN="KLIF"/>
 </RK_KM>
 <RK_IRP>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="0" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="2" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="4" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="5" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="6" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="7" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="8" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="10" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="11" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="12" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="13" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="14" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="17" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="20" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="21" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\ntfs" IRP="27" HookPtr="84F801F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="0" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="2" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="4" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="5" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="6" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="7" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="8" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="10" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="11" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="12" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="13" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="14" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="17" HookPtr="85A0B1F8"/>
  <ITEM File="" DeviceName="\FileSystem\FastFat" IRP="27" HookPtr="85A0B1F8"/>
 </RK_IRP>
 <WIZARD-TSW>
  <ITEM ID="16" Level="3" Fixed="0" />
  <ITEM ID="17" Level="2" Fixed="0" />
  <ITEM ID="18" Level="3" Fixed="0" />
  <ITEM ID="19" Level="2" Fixed="0" />
  <ITEM ID="20" Level="3" Fixed="0" />
  <ITEM ID="51" Level="2" Fixed="0" />
  <ITEM ID="58" Level="3" Fixed="0" />
  <ITEM ID="59" Level="3" Fixed="0" />
  <ITEM ID="61" Level="2" Fixed="0" />
  <ITEM ID="65" Level="3" Fixed="0" />
 </WIZARD-TSW>
</AVZ>
