Balabala | 13.03.2015 01:32 | Teil2: Code:
</Service>
-<Drivers>
<ITEM IsPE="1" Ver="9.2.0.427" OFN="ATHR.SYS" Product="Driver for Atheros CB42/CB43/MB42/MB43 Network Adapter" Vendor="Atheros Communications, Inc." MD5="A5E770426D18F8EF332A593F3289DA91" ChangeDate="21.06.2011 01:03:42" CreateDate="20.02.2015 17:46:30" Attr="rsAh" Size="2753536" CheckResult="-1" File="C:\Windows\system32\DRIVERS\athrx.sys" IsPE64="1" State="4" Type="1" Name="athr"/>
<ITEM IsPE="1" Ver="14.0.6.524" OFN="avgntflt_ld.sys" Product="Avira Product Family" Vendor="Avira Operations GmbH & Co. KG" MD5="1B87A1F2FA5B91AC1A7D171B8D952441" ChangeDate="09.10.2014 13:53:44" CreateDate="12.06.2013 21:18:38" Attr="rsAh" Size="119272" CheckResult="-1" File="C:\Windows\system32\DRIVERS\avgntflt.sys" IsPE64="1" State="4" Type="2" Name="avgntflt"/>
<ITEM IsPE="1" Ver="14.0.7.186" OFN="avipbb.sys" Product="Avira Product Family" Vendor="Avira Operations GmbH & Co. KG" MD5="AF61774060F277FE45CBD3A9A8E7D45A" ChangeDate="09.10.2014 13:53:45" CreateDate="12.06.2013 21:18:38" Attr="rsAh" Size="131608" CheckResult="-1" File="C:\Windows\system32\DRIVERS\avipbb.sys" IsPE64="1" State="4" Type="1" Name="avipbb"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\drivers\MBAMSwissArmy.sys" State="1" Type="2" Name="MBAMSwissArmy"/>
</Drivers>
-<AUTORUN>
<ITEM CheckResult="-1" File="2014\TuneUpUtilitiesService64.exe" Type="REG" Is64="0" X4="C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\TuneUp\TuneUp.UtilitiesSvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" Type="REG" Is64="1" X4=""C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"" X3="command" X2="SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe" Type="REG" Is64="0" X4="C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe" X3="AudialsNotifier" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_CURRENT_USER" Enabled="1"/>
<ITEM IsPE="1" Ver="1.1.32.25159" OFN="Avira.OE.Systray.exe" Product="Avira.OE.Systray" Vendor="Avira Operations GmbH & Co. KG" MD5="8CB85437667AEDBD8497D2CA85F4A17A" ChangeDate="12.02.2015 14:00:14" CreateDate="12.02.2015 14:00:14" Attr="rsAh" Size="127792" CheckResult="-1" File="C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe" Type="REG" Is64="0" X4="C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe" X3="Avira Systray" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\IPSEventLogMsg.dll" Type="REG" Is64="0" X4="%CommonProgramFiles%\Microsoft Shared\Ink\IPSEventLogMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Handwriting Recognition" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\DVD" Type="REG" Is64="0" X4="%ProgramFiles%\DVD Maker\DVDMaker.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Lavasoft\Web" Type="REG" Is64="0" X4="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize" X3="Web Companion" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_CURRENT_USER" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE" Type="REG" Is64="0" X4="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\BBSvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE" Type="REG" Is64="0" X4="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\SeaPort" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM IsPE="1" Ver="4.0.9775.500" OFN="shlxthdl.dll" Vendor="Apache Software Foundation" MD5="32BA5DF7E70E7FA46C0AB956FB2515FD" ChangeDate="13.08.2014 09:27:46" CreateDate="13.08.2014 09:27:46" Attr="rsAh" Size="853504" CheckResult="-1" File="C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll" IsPE64="1" IsDLL="1" Type="REG" Is64="1" X4="LibreOffice Infotip Handler" X3="{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM IsPE="1" Ver="4.0.9775.500" OFN="shlxthdl.dll" Vendor="Apache Software Foundation" MD5="32BA5DF7E70E7FA46C0AB956FB2515FD" ChangeDate="13.08.2014 09:27:46" CreateDate="13.08.2014 09:27:46" Attr="rsAh" Size="853504" CheckResult="-1" File="C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll" IsPE64="1" IsDLL="1" Type="REG" Is64="1" X4="LibreOffice Thumbnail Viewer" X3="{3B092F0C-7696-40E3-A80F-68D74DA84210}" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM IsPE="1" Ver="4.0.9775.500" OFN="shlxthdl.dll" Vendor="Apache Software Foundation" MD5="32BA5DF7E70E7FA46C0AB956FB2515FD" ChangeDate="13.08.2014 09:27:46" CreateDate="13.08.2014 09:27:46" Attr="rsAh" Size="853504" CheckResult="-1" File="C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll" IsPE64="1" IsDLL="1" Type="REG" Is64="1" X4="LibreOffice Property Sheet Handler" X3="{63542C48-9552-494A-84F7-73AA6A7C99C1}" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM IsPE="1" Ver="4.0.9775.500" OFN="shlxthdl.dll" Vendor="Apache Software Foundation" MD5="32BA5DF7E70E7FA46C0AB956FB2515FD" ChangeDate="13.08.2014 09:27:46" CreateDate="13.08.2014 09:27:46" Attr="rsAh" Size="853504" CheckResult="-1" File="C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll" IsPE64="1" IsDLL="1" Type="REG" Is64="1" X4="LibreOffice Column Handler" X3="{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" X2="Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\TuneUp" Type="REG" Is64="0" X4="C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\TuneUp\TuneUp.UtilitiesSvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Program Files (x86)\Windows Defender\MpEvMsg.dll" Type="REG" Is64="0" X4="%ProgramFiles%\Windows Defender\MpEvMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM IsPE="1" Ver="5.3.0.5128" OFN="ccleaner.exe" Product="CCleaner" Vendor="Piriform Ltd" MD5="845799C9874B68BEAE3B64059653C7E3" ChangeDate="19.02.2015 17:40:12" CreateDate="19.02.2015 17:40:12" Attr="rsAh" Size="7416088" CheckResult="-1" File="C:\Program Files\CCleaner\CCleaner64.exe" IsPE64="1" Type="REG" Is64="0" X4=""C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR" X3="CCleaner Monitoring" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_CURRENT_USER" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Program Files\Vodafone\Vodafone" Type="REG" Is64="0" X4="%programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent" X3="MobileConnect" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" Type="REG" Is64="0" X4=""C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"" X3="CitrixReceiver" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\ActiveCare" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\DriveScrubber" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\Installer" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\Search and Recover" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\Service Manager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\System Guard" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\System Mechanic" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" Type="REG" Is64="0" X4="C:\Users\T\AppData\Roaming\iolo\EventMsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\iolo Applications\System Shield" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Audiosrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\Audiosrv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Audiosrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\Audiosrv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\AxInstSV.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\AxInstSV.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AxInstSV\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\AxInstSv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\AxInstSv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-AxInstallService" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\DFDTS.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\DFDTS.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Disk Diagnostic" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\DispCI.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\DispCI.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Display" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\BthUsb.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\BthUsb.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\Bthport.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\Bthport.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHPORT" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\Bthport.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\Bthport.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\BTHUSB" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\Pcmcia.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\Pcmcia.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\VolSnap.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\VolSnap.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Volsnap" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\acpi.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\acpi.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\ACPI" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\Drivers\hidbth.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\Drivers\hidbth.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\HidBth" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\MsSpellCheckingFacility.dll" Type="REG" Is64="0" X4="%systemroot%\System32\MsSpellCheckingFacility.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Spell-Checking" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\MsSpellCheckingFacility.dll" Type="REG" Is64="0" X4="%systemroot%\System32\MsSpellCheckingFacility.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-SpellChecker" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\MsSpellCheckingFacility.dll" Type="REG" Is64="0" X4="%systemroot%\System32\MsSpellCheckingFacility.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Spell-Checking" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\MsSpellCheckingFacility.dll" Type="REG" Is64="0" X4="%systemroot%\System32\MsSpellCheckingFacility.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SpellChecker" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\RpcEpMap.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\RpcEpMap.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\RpcEptMapper\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\SCardSvr.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\SCardSvr.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SCardSvr\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\SDRSVC.dll" Type="REG" Is64="0" X4="%Systemroot%\System32\SDRSVC.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SDRSVC\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\TabSvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\TabSvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\TabletInputService\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll" Type="REG" Is64="1" X4="C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll" X3="DLLName" X2="Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\UI0Detect.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\UI0Detect.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Interactive Services detection" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\VSSVC.EXE" Type="REG" Is64="0" X4="%SystemRoot%\System32\VSSVC.EXE" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\VSSVC.EXE" Type="REG" Is64="0" X4="%SystemRoot%\System32\VSSVC.EXE" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Security\VSSAudit" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\WUDFHost.exe" Type="REG" Is64="1" X4="C:\Windows\System32\WUDFHost.exe" X3="HostProcessImagePath" X2="Software\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\WUDFSvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\WUDFSvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\wudfsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\WerSvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\WerSvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\WerSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\aelupsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\aelupsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AeLookupSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\aelupsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\aelupsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\AeLookupSvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\appidsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\appidsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AppIDSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\appinfo.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\appinfo.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Appinfo\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\appmgmts.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\appmgmts.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\bdesvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\bdesvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\BDESVC\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\bfe.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\bfe.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\BFE\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\browser.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\browser.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Browser\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\certprop.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\certprop.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\CertPropSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\certprop.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\certprop.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SCPolicySvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\defragsvc.dll" Type="REG" Is64="0" X4="%Systemroot%\System32\defragsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\defragsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\dnsrslvr.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\dnsrslvr.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Dnscache\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\dot3svc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\dot3svc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\dot3svc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\ArcSoftKsUFilter.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\ArcSoftKsUFilter.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\ArcSoftKsUFilter" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\HECIx64.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\HECIx64.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\MEIx64" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\MTConfig.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\MTConfig.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\MTConfig" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\Rt64win7.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\Rt64win7.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\RTL8167" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\Wdf01000.sys" Type="REG" Is64="0" X4="C:\Windows\System32\drivers\Wdf01000.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\wdf01000" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\amdk8.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\amdk8.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdK8" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\amdppm.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\amdppm.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\AmdPPM" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\avgntflt.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\avgntflt.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\avgntflt" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\avipbb.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\avipbb.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\avipbb" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\avkmgr.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\avkmgr.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\avkmgr" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\b57nd60a.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\b57nd60a.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\b57nd60a" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\btath_hcrp.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\btath_hcrp.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\BTATH_HCRP" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\bxvbda.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\bxvbda.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\b06bdrv" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\e1y60x64.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\e1y60x64.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\e1yexpress" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\evbda.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\evbda.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\ebdrv" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\fltmgr.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\fltmgr.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\FltMgr" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\i8042prt.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\i8042prt.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\iaStor.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\iaStor.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStor" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\iaStorV.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\iaStorV.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStorV" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\intelppm.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\intelppm.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\ipmidrv.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\ipmidrv.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMIDRV" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\isapnp.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\isapnp.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\kbdclass.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\kbdclass.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\kbdhid.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\kbdhid.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\mouclass.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\mouclass.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\mouhid.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\mouhid.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\mpio.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\mpio.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\mpio" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\nvstor.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\nvstor.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\nvstor" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\parport.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\parport.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\processr.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\processr.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Processor" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\sbp2port.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\sbp2port.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\sbp2port" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\serial.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\serial.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Serial" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\sermouse.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\sermouse.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\tsusbflt.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\tsusbflt.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\TsUsbFlt" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\vgapnp.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\vgapnp.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\vga" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\wacompen.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\wacompen.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\WacomPen" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\drivers\wd.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\drivers\wd.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Wd" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\eapsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\eapsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\EapHost\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\gpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\gpsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\gpsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\ikeext.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\ikeext.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\IKEEXT\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\iphlpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\iphlpsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\ipnathlp.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\ipnathlp.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\ipsecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\ipsecsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\PolicyAgent\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\iscsiexe.dll" Type="REG" Is64="0" X4="%systemroot%\System32\iscsiexe.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\MSiSCSI" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\iscsilog.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\iscsilog.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\iScsiPrt" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\lltdsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\lltdsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\lltdsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\lmhsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\lmhsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\lmhosts\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\lsasrv.dll" Type="REG" Is64="0" X4="%windir%\System32\lsasrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\lsasrv.dll" Type="REG" Is64="0" X4="%windir%\System32\lsasrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\mdsched.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\mdsched.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Schedule" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\netman.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\netman.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Netman\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\nlasvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\nlasvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\pcasvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\pcasvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\PcaSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\profsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\profsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-User Profiles Service" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\profsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\profsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Profsvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\qmgr.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\qmgr.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\BITS\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\rasauto.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\rasauto.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\RasAuto\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\rasmans.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\rasmans.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\RasMan\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\relpost.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\relpost.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-MemoryDiagnostics-Results" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\samsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\samsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Directory-Services-SAM" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\samsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\samsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\snmptrap.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\snmptrap.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\SNMPTRAP" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\srvsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\srvsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\ssdpsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\ssdpsrv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\sstpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\sstpsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-RasSstp" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\swprv.dll" Type="REG" Is64="0" X4="%Systemroot%\System32\swprv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\swprv\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\tbssvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\tbssvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\TBS\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\tcpmon.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\tcpmon.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\termsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\termsrv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\TermService\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\trkwks.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\trkwks.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\TrkWks\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\umpnpmgr.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\umpnpmgr.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\umpo.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\umpo.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Power" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\uxsms.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\uxsms.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\UxSms\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\vds.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\vds.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Virtual Disk Service" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wbiosrvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wbiosrvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\WbioSrvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wecsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\wecsvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wercplsupport.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wercplsupport.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\wercplsupport\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wersvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wersvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wersvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wersvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\WerSvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wevtsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wevtsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Security\Microsoft-Windows-Eventlog" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wevtsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wevtsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Eventlog" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wiaservc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wiaservc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\stisvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wiaservc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wiaservc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\win32k.sys" Type="REG" Is64="0" X4="\SystemRoot\System32\win32k.sys" X3="Kmode" X2="System\CurrentControlSet\Control\Session Manager\SubSystems" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\win32k.sys" Type="REG" Is64="0" X4="%SystemRoot%\System32\win32k.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\winlogon.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\winlogon.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\winlogon.exe" Type="REG" Is64="0" X4="%SystemRoot%\System32\winlogon.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wlclntfy" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wkssvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wkssvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wlansvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wlansvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Wlansvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wscsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wscsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\System32\wwansvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\System32\wwansvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\WwanSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\BlbEvents.dll" Type="REG" Is64="0" X4="%windir%\system32\BlbEvents.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Backup" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\FntCache.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\FntCache.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\FontCache\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\ListSvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\ListSvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\HomeGroupListener\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\Mcx2Svc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\Mcx2Svc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Mcx2Svc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\WINSAT.EXE" Type="REG" Is64="0" X4="%SystemRoot%\system32\WINSAT.EXE" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-WindowsSystemAssessmentTool" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\WUDFPlatform.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\WUDFPlatform.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DriverFrameworks-UserMode" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\Wat\WatUX.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\Wat\WatUX.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Activation Technologies" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\bthserv.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\bthserv.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\bthserv\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\certprop.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\certprop.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-SCPNP" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\cofiredm.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\cofiredm.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Client" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\cofiredm.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\cofiredm.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-CorruptedFileRecovery-Server" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\csrsrv.dll" Type="REG" Is64="0" X4="%windir%\system32\csrsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Subsys-SMSS" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\defragsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\defragsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Defrag" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\dfdts.dll" Type="REG" Is64="0" X4="%windir%\system32\dfdts.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-DiskDiagnostic" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\dps.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\dps.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\DPS\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\drivers\HTTP.SYS" Type="REG" Is64="0" X4="%SystemRoot%\system32\drivers\HTTP.SYS" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HttpEvent" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\drivers\fltmgr.sys" Type="REG" Is64="0" X4="%SystemRoot%\system32\drivers\fltmgr.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FilterManager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\drivers\fvevol.sys" Type="REG" Is64="0" X4="%SystemRoot%\system32\drivers\fvevol.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-Driver" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\drivers\ntfs.sys" Type="REG" Is64="0" X4="%SystemRoot%\system32\drivers\ntfs.sys" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Ntfs" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM IsPE="1" Ver="12.0.116.0" OFN="DVMsg.DLL" Product="David Message Library" MD5="E73337EEA029D9A640FBBA6C1260FB48" ChangeDate="03.01.2012 11:38:04" CreateDate="01.03.2014 18:52:14" Attr="rsAh" Size="2681344" CheckResult="-1" File="C:\Windows\system32\dvmsg.dll" IsDLL="1" Type="REG" Is64="0" X4="C:\Windows\system32\dvmsg.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Radio.fx" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\dwm.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\dwm.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Desktop Window Manager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\eapsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\eapsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EapHost" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fdPHost.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\fdPHost.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\fdPHost\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fdphost.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\fdphost.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-FunctionDiscoveryHost" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fdrespub.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\fdrespub.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\FDResPub\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fdrespub.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\fdrespub.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-ResourcePublication" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fveapi.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\fveapi.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-BitLocker-API" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\fxsevent.dll" Type="REG" Is64="0" X4="%systemroot%\system32\fxsevent.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Fax" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\gpsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\gpsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-GroupPolicy" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\hkcmd.exe" Type="REG" Is64="1" X4="C:\Windows\system32\hkcmd.exe" X3="HotKeysCmds" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\igfxpers.exe" Type="REG" Is64="1" X4="C:\Windows\system32\igfxpers.exe" X3="Persistence" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\igfxtray.exe" Type="REG" Is64="1" X4="C:\Windows\system32\igfxtray.exe" X3="IgfxTray" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\ipbusenum.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\ipbusenum.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\IPBusEnum\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\ipbusenum.dll" Type="REG" Is64="0" X4="%systemroot%\system32\ipbusenum.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-IPBusEnum" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\iphlpsvc.dll" Type="REG" Is64="0" X4="%windir%\system32\iphlpsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Iphlpsvc" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\iscsiexe.dll" Type="REG" Is64="0" X4="%systemroot%\system32\iscsiexe.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\MSiSCSI\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\kmsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\kmsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\lpksetup.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\lpksetup.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-LanguagePackSetup" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\lsm.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\lsm.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\LSM" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\lsm.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\lsm.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-LocalSessionManager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\microsoft-windows-hal-events.dll" Type="REG" Is64="0" X4="%systemroot%\system32\microsoft-windows-hal-events.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-HAL" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\microsoft-windows-kernel-power-events.dll" Type="REG" Is64="0" X4="%systemroot%\system32\microsoft-windows-kernel-power-events.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Power" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll" Type="REG" Is64="0" X4="%systemroot%\system32\microsoft-windows-kernel-processor-power-events.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Kernel-Processor-Power" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\mmcss.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\mmcss.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\MMCSS\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\mmcss.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\mmcss.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\THREADORDER\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\mpssvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\mpssvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\MpsSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\mpssvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\mpssvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Firewall" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\msdtckrm.dll" Type="REG" Is64="0" X4="%systemroot%\system32\msdtckrm.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\KtmRm\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\nsisvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\nsisvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\nsi\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\oobe\winsetup.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\oobe\winsetup.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Setup" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\p2psvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\p2psvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\p2psvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\pnrpauto.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\pnrpauto.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\PNRPAutoReg\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\pnrpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\pnrpsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\p2pimsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\pnrpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\pnrpsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\PNRPsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\profsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\profsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\ProfSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\psxss.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\psxss.exe" X3="Posix" X2="System\CurrentControlSet\Control\Session Manager\SubSystems" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\qagentRT.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\qagentRT.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\napagent\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\qmgr.dll" Type="REG" Is64="0" X4="%systemroot%\system32\qmgr.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Bits-Client" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\recovery.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\recovery.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Recovery" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\regsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\regsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\rpcss.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\rpcss.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\rpcss.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\rpcss.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\RpcSs\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\schedsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\schedsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Schedule\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\schedsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\schedsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TaskScheduler" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sdclt.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\sdclt.exe" X3="" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sdengin2.dll" Type="REG" Is64="0" X4="%systemroot%\system32\sdengin2.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Backup" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\seclogon.dll" Type="REG" Is64="0" X4="%windir%\system32\seclogon.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\seclogon\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sensrsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\sensrsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SensrSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\services.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\services.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sppsvc.exe" Type="REG" Is64="0" X4="%windir%\system32\sppsvc.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Protection Platform Service" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sppsvc.exe" Type="REG" Is64="0" X4="%windir%\system32\sppsvc.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Key Management Service\KmsRequests" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sppuinotify.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\sppuinotify.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\sppuinotify\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\srcore.dll" Type="REG" Is64="0" X4="%systemroot%\system32\srcore.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\System Restore" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sstpsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\sstpsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sstpsvc.dll" Type="REG" Is64="0" X4="%systemroot%\system32\sstpsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\RasSstp" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sysmain.dll" Type="REG" Is64="0" X4="%systemroot%\system32\sysmain.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\SysMain\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\sysmain.dll" Type="REG" Is64="0" X4="%systemroot%\system32\sysmain.dll" X3="Library" X2="SYSTEM\CurrentControlSet\Services\rdyboost\Performance" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\tbssvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\tbssvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TBS" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\termsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\termsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-TerminalServices-RemoteConnectionManager" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\termsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\termsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\TermService" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\themeservice.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\themeservice.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Themes\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\umpnpmgr.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\umpnpmgr.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\PlugPlay\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\umpnpmgr.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\umpnpmgr.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-UserPnp" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\umpo.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\umpo.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Power\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\w32time.dll" Type="REG" Is64="0" X4="%systemroot%\system32\w32time.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\W32Time\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\w32time.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\w32time.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Time-Service" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\w32time.dll" Type="REG" Is64="0" X4="%Systemroot%\system32\w32time.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\w32time.dll" Type="REG" Is64="0" X4="%systemroot%\system32\w32time.dll" X3="DllName" X2="SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\w32time.dll" Type="REG" Is64="0" X4="%systemroot%\system32\w32time.dll" X3="DllName" X2="SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wbem\WMIsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wbem\WMIsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wecsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\Wecsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wecsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-EventCollector" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wecsvc.dll" X3="DisplayNameFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\HardwareEvents" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wecsvc.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wecsvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-EventCollector" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\winlogon.exe" Type="REG" Is64="0" X4="%SystemRoot%\system32\winlogon.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-Winlogon" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\winsrv.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\winsrv.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-Winsrv" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wlansvc.dll" Type="REG" Is64="0" X4="%windir%\system32\wlansvc.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WLAN-AutoConfig" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wpdbusenum.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wpdbusenum.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\WPDBusEnum\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wscsvc.dll" Type="REG" Is64="0" X4="%SYSTEMROOT%\system32\wscsvc.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\wscsvc\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wsepno.dll" Type="REG" Is64="0" X4="%SystemRoot%\system32\wsepno.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Search Service Profile Notification" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wuaueng.dll" Type="REG" Is64="0" X4="%systemroot%\system32\wuaueng.dll" X3="ServiceDll" X2="SYSTEM\CurrentControlSet\Services\wuauserv\Parameters" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="C:\Windows\system32\wuaueng.dll" Type="REG" Is64="0" X4="%systemroot%\system32\wuaueng.dll" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\System\Microsoft-Windows-WindowsUpdateClient" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="Companion\Application\WebCompanion.exe" Type="REG" Is64="0" X4="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize" X3="Web Companion" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_CURRENT_USER" Enabled="1"/>
<ITEM CheckResult="-1" File="Connect\Bin\MobileConnect.exe" Type="REG" Is64="0" X4="%programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent" X3="MobileConnect" X2="Software\Microsoft\Windows\CurrentVersion\Run" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="D:\099c55cc6e42fa12058f\DW\DW20.exe" Type="REG" Is64="0" X4="D:\099c55cc6e42fa12058f\DW\DW20.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSSetup" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="Maker\DVDMaker.exe" Type="REG" Is64="0" X4="%ProgramFiles%\DVD Maker\DVDMaker.exe" X3="EventMessageFile" X2="SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dvd Maker" X1="HKEY_LOCAL_MACHINE" Enabled="-1"/>
<ITEM CheckResult="-1" File="auditcse.dll" Type="REG" Is64="1" X4="auditcse.dll" X3="DLLName" X2="Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
<ITEM CheckResult="-1" File="igfxdev.dll" Type="REG" Is64="1" X4="igfxdev.dll" X3="DLLName" X2="Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" X1="HKEY_LOCAL_MACHINE" Enabled="1"/>
</AUTORUN>
-<BHO>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll" Enabled="1" CLSID="{d2ce3e00-f94a-4740-988e-03dc2f38c34f}" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" BHOType="1"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll" Enabled="1" CLSID="{DBC80044-A445-435b-BC74-9C25C1C588A9}" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" BHOType="1"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll" Enabled="1" CLSID="{8dcb7100-df86-4384-8842-8fa844297b3f}" RegKey="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" BHOType="2"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="" Enabled="1" CLSID="{7815BE26-237D-41A8-A98F-F7BD75F71086}" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" BHOType="3"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="" Enabled="1" CLSID="{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}" RegKey="HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions" BHOType="3"/>
</BHO>
-<ExplorerExt>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="" Enabled="1" CLSID="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" ExtName="WebCheck" ExtType="1"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="" Enabled="1" CLSID="{126F4AE6-31EC-4A1E-AC60-B1E5FF812C3D}" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" ExtName="PDF Architect Context Menu Extension" ExtType="1"/>
</ExplorerExt>
-<PrintEXT>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="CNMLMA4.DLL" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="localspl.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="FXSMON.DLL" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="pdfcmon.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="tcpmon.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="usbmon.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="WSDMon.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="inetpp.dll" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Providers"/>
</PrintEXT>
-<TaskScheduler>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Users\T\AppData\Roaming\NU.exe" Enabled="49961344" FullCmd="C:\Users\T\AppData\Roaming\NU.exe /infocmdline=sLtVqwayOR0MkCuQ+6X6e5LmlgP+ZnGDEG8RK88MrQjl/RsqEZex9DDhuexGpWeC7SNwubiwISsNcyxYKJ2Lbi927/Myy4FPo32mTXUocfsNpdO3wPJfNZp9senq9mJ6bmLlvuYdMSrvGdYJP1qH3CCuCcjNN+WIOL/ezOueci9n2+sdKNYmiBB6Zxu1/C999XWAqmmwz3y/dsvqmMYvYfPSbjMEtVqtFyKddxm90ume0fzVpSy8WxB4lC93MN0Tzxqljff81lC+T9ViegLzAgeaT70VYK3KPqpEsfmdlU23GTsc4bQ7J0bfD7qj6Q5RhrZ8ff8T4KIf7NVWAvtU9QNAFO/Akhopjn9S+Y76twG/IW8qnfrT1GkugMWWXWWGptkuYafi0OuODsjahYCoccph7UR8n7E8pzWStn3kpOdg4mxBqymLKai8BnD6ruQtMS10y4bD2E+bGeXJ+bFATpvJQqnia+9iooISFLs7MyVYORgINikhn2Z+LM8e/GvK" SHPath="" Status="267008" JobName="NU.job"/>
<ITEM IsPE="1" Ver="5.3.0.5128" OFN="ccleaner.exe" Product="CCleaner" Vendor="Piriform Ltd" MD5="2B24F194FC5B657397ECB2923A68350E" ChangeDate="19.02.2015 17:40:12" CreateDate="19.02.2015 17:40:12" Attr="rsAh" Size="5503768" LegalCopyright="Copyright © 2005-2015 Piriform Ltd" Descr="CCleaner" CheckResult="-1" File="C:\Program Files\CCleaner\CCleaner.exe" Enabled="49961344" FullCmd=" "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="CCleanerSkipUAC"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\MyPC" Enabled="49961344" FullCmd=" C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe frompopup" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="LaunchSignup"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="Wizard.exe" Enabled="49961344" FullCmd=" C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe frompopup" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="LaunchSignup"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File=" aitagent " Enabled="49961344" FullCmd=" aitagent " SHPath="C:\Windows\system32\Tasks\Microsoft\Windows\Application Experience\" Status="23650952" JobName="AitAgent"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Windows\ehome\mcupdate" Enabled="49961344" FullCmd=" %SystemRoot%\ehome\mcupdate $(Arg0)" SHPath="C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\" Status="23650952" JobName="mcupdate"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Windows\ehome\mcupdate" Enabled="49961344" FullCmd=" %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15" SHPath="C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\" Status="23650952" JobName="mcupdate_scheduled"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Windows\ehome\ehrec" Enabled="49961344" FullCmd=" %SystemRoot%\ehome\ehrec /RestartRecording" SHPath="C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\" Status="23650952" JobName="RecordingRestart"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Windows\ehome\ehrec" Enabled="49961344" FullCmd=" %SystemRoot%\ehome\ehrec /StartRecording" SHPath="C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\" Status="23650952" JobName="StartRecording"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Users\T\AppData\Roaming\NU.exe" Enabled="49961344" FullCmd=" C:\Users\T\AppData\Roaming\NU.exe /infocmdline=sLtVqwayOR0MkCuQ+6X6e5LmlgP+ZnGDEG8RK88MrQjl/RsqEZex9DDhuexGpWeC7SNwubiwISsNcyxYKJ2Lbi927/Myy4FPo32mTXUocfsNpdO3wPJfNZp9senq9mJ6bmLlvuYdMSrvGdYJP1qH3CCuCcjNN+WIOL/ezOueci9n2+sdKNYmiBB6Zxu1/C999XWAqmmwz3y/dsvqmMYvYfPSbjMEtVqtFyKddxm90ume0fzVpSy8WxB4lC93MN0Tzxqljff81lC+T9ViegLzAgeaT70VYK3KPqpEsfmdlU23GTsc4bQ7J0bfD7qj6Q5RhrZ8ff8T4KIf7NVWAvtU9QNAFO/Akhopjn9S+Y76twG/IW8qnfrT1GkugMWWXWWGptkuYafi0OuODsjahYCoccph7UR8n7E8pzWStn3kpOdg4mxBqymLKai8BnD6ruQtMS10y4bD2E+bGeXJ+bFATpvJQqnia+9iooISFLs7MyVYORgINikhn2Z+LM8e/GvK" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="NU"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\Ask.com\UpdateTask.exe" Enabled="49961344" FullCmd=" C:\Program Files (x86)\Ask.com\UpdateTask.exe " SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="Scheduled Update for Ask Toolbar"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files\Sony\VAIO Gate\VAIO" Enabled="49961344" FullCmd=" C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe /AutoStart" SHPath="C:\Windows\system32\Tasks\SONY\VAIO Gate\" Status="23651340" JobName="VAIO Gate"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="Gate.exe" Enabled="49961344" FullCmd=" C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe /AutoStart" SHPath="C:\Windows\system32\Tasks\SONY\VAIO Gate\" Status="23651340" JobName="VAIO Gate"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files\Sony\VAIO Smart Network\VSNClient" Enabled="49961344" FullCmd=" C:\Program Files\Sony\VAIO Smart Network\VSNClient /Start" SHPath="C:\Windows\system32\Tasks\Sony Corporation\VAIO Smart Network\" Status="23651340" JobName="VSN Logon Start"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files (x86)\Sony\Xperia Link\Xperia" Enabled="49961344" FullCmd=" C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe /AutoStart" SHPath="C:\Windows\system32\Tasks\Sony Corporation\Xperia Link\" Status="23651340" JobName="Xperia Link Logon Start"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="Link.exe" Enabled="49961344" FullCmd=" C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe /AutoStart" SHPath="C:\Windows\system32\Tasks\Sony Corporation\Xperia Link\" Status="23651340" JobName="Xperia Link Logon Start"/>
<ITEM MD5="5835442999D7DDF327A99DB0633B8E19" ChangeDate="20.02.2015 18:44:24" CreateDate="20.02.2015 18:44:24" Attr="rsAh" Size="174" LegalCopyright="" Descr="" CheckResult="-1" File="C:\Program Files\Sony\VAIO Care\ESRV\task.vbs" Enabled="49961344" FullCmd=" "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="USER_ESRV_SVC"/>
<ITEM IsPE="1" Ver="14.1.0.0" OFN="CtxInstall.exe" Product="Citrix ICA Client" Vendor="Citrix Systems, Inc." MD5="ACAFB4C0554C1FB36268F519A2049BD6" ChangeDate="01.10.2013 18:05:08" CreateDate="21.07.2014 18:53:41" Attr="rsAh" Size="1448328" LegalCopyright="Copyright (c) 1990-2013 Citrix Systems, Inc." Descr="Citrix Installation" CheckResult="-1" File="C:\ProgramData\Citrix\Citrix Receiver\TrolleyExpress.exe" Enabled="49961344" FullCmd=" C:\Windows\system32\pcalua.exe -a "C:\ProgramData\Citrix\Citrix Receiver\TrolleyExpress.exe" -c /uninstall /cleanup" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="{151C49F3-4B51-4465-B9F6-B920AC9B7D0F}"/>
<ITEM IsPE="1" Ver="11.0.50800.0" OFN="Audials Radiotracker" Product="Audials Radiotracker" Vendor="RapidSolution Software AG" MD5="4F0B7CBEED2E567C45350EDA396801C3" ChangeDate="01.03.2014 19:08:36" CreateDate="01.03.2014 19:08:35" Attr="rsAh" Size="1699496" LegalCopyright="© 2004-2010 by RapidSolution Software AG" Descr="Audials Radiotracker" CheckResult="-1" File="C:\temp\AudialsRadiotracker11_CBE.exe" Enabled="49961344" FullCmd=" C:\Windows\system32\pcalua.exe -a C:\temp\AudialsRadiotracker11_CBE.exe -d C:\temp" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="{7DAB22D2-CF69-4EA0-B501-053C26E74567}"/>
<ITEM LegalCopyright="" Descr="" CheckResult="-1" File="D:\Setup.exe" Enabled="49961344" FullCmd=" C:\Windows\system32\pcalua.exe -a D:\Setup.exe -d D:\" SHPath="C:\Windows\system32\Tasks\" Status="23652116" JobName="{A0B53BE8-D194-4590-B880-EA451E7D2F16}"/>
</TaskScheduler>
-<SPI>
<ITEM IsPE="1" Ver="6.1.7601.18685" OFN="nlaapi.dll" Product="Microsoft® Windows® Operating System" Vendor="Microsoft Corporation" MD5="FE48346938C1CDDDF4E4097DB9B99764" ChangeDate="06.12.2014 04:50:19" CreateDate="14.01.2015 00:56:25" Attr="rsAh" Size="52224" LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="Network Location Awareness 2" CheckResult="-1" File="C:\Windows\system32\NLAapi.dll" IsDLL="1" SPINaim="@%SystemRoot%\system32\nlasvc.dll,-1000" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="napinsp.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="0B7E85364CB878E2AD531DB7B601A9E5" ChangeDate="14.07.2009 02:16:02" CreateDate="14.07.2009 00:54:55" Attr="rsAh" Size="52224" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="E-Mail-Namenshimanbieter" CheckResult="-1" File="C:\Windows\system32\napinsp.dll" IsDLL="1" SPINaim="@%SystemRoot%\system32\napinsp.dll,-1000" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="pnrpnsp.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="5CF640EDDB1E40A5AB1BB743BCDEC610" ChangeDate="14.07.2009 02:16:12" CreateDate="14.07.2009 00:55:50" Attr="rsAh" Size="65024" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="PNRP-Namespaceanbieter" CheckResult="-1" File="C:\Windows\system32\pnrpnsp.dll" IsDLL="1" SPINaim="@%SystemRoot%\system32\pnrpnsp.dll,-1000" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="pnrpnsp.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="5CF640EDDB1E40A5AB1BB743BCDEC610" ChangeDate="14.07.2009 02:16:12" CreateDate="14.07.2009 00:55:50" Attr="rsAh" Size="65024" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="PNRP-Namespaceanbieter" CheckResult="-1" File="C:\Windows\system32\pnrpnsp.dll" IsDLL="1" SPINaim="@%SystemRoot%\system32\pnrpnsp.dll,-1001" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\System32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\system32\wshtcpip.dll,-60103" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="winrnr" Product="Microsoft® Windows® Operating System" Vendor="Microsoft Corporation" MD5="5DF5D8CFD9B9573FA3B2C89D9061A240" ChangeDate="14.07.2009 02:16:19" CreateDate="14.07.2009 00:37:57" Attr="rsAh" Size="20992" LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="LDAP RnR Provider DLL" CheckResult="-1" File="C:\Windows\System32\winrnr.dll" IsDLL="1" SPINaim="NTDS" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7601.17514" OFN="wshbth.dll" Product="Microsoft® Windows® Operating System" Vendor="Microsoft Corporation" MD5="AC122407B29378FF9646F03404AC7C54" ChangeDate="21.11.2010 04:24:50" CreateDate="21.11.2010 04:24:50" Attr="rsAh" Size="36352" LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="Windows Sockets Helper DLL" CheckResult="-1" File="C:\Windows\system32\wshbth.dll" IsDLL="1" SPINaim="Bluetooth-Namespace" SPIType="1"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wship6.dll,-60100" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wship6.dll,-60101" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wship6.dll,-60102" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60100" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60101" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshtcpip.dll,-60102" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshqos.dll,-100" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshqos.dll,-101" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshqos.dll,-102" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="@%SystemRoot%\System32\wshqos.dll,-103" SPIType="3"/>
<ITEM IsPE="1" Ver="6.1.7601.18254" OFN="mswsock.dll.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="E94C583CDE2348950155F2AF2876F34D" ChangeDate="08.09.2013 03:03:58" CreateDate="10.10.2013 21:37:04" Attr="rsAh" Size="231424" LegalCopyright="© Microsoft Corporation. Alle Rechte vorbehalten." Descr="Microsoft Windows Sockets 2.0-Dienstanbieter" CheckResult="-1" File="C:\Windows\system32\mswsock.dll" IsDLL="1" SPINaim="MSAFD RfComm [Bluetooth]" SPIType="3"/>
</SPI>
-<PORTS>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="135" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="139" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="445" PortType="1"/>
<ITEM CheckResult="-1" File="wmpnetwk.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="554" PortType="1"/>
<ITEM CheckResult="-1" File="" RemoteHost="127.0.0.1" RemotePort="49925" LocalPort="2869" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="2869" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="5357" PortType="1"/>
<ITEM CheckResult="-1" File="VCSystemTray.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="9996" PortType="1"/>
<ITEM CheckResult="-1" File="VCAdmin.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="9998" PortType="1"/>
<ITEM CheckResult="-1" File="VCAgent.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="9999" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="10243" PortType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="WinInit.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="B5C5DCAD3899512020D135600129D665" ChangeDate="14.07.2009 02:14:45" CreateDate="14.07.2009 00:36:49" Attr="rsAh" Size="96256" CheckResult="0" File="C:\Windows\system32\wininit.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="49152" PortType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="49153" PortType="1"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="49154" PortType="1"/>
<ITEM CheckResult="-1" File="lsass.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="49155" PortType="1"/>
<ITEM CheckResult="-1" File="services.exe" RemoteHost="0.0.0.0" RemotePort="0" LocalPort="49156" PortType="1"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="" RemotePort="0" LocalPort="137" PortType="2"/>
<ITEM CheckResult="-1" File="System.exe" RemoteHost="" RemotePort="0" LocalPort="138" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="500" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="1900" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="1900" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="3702" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="3702" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="3702" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="3702" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="4500" PortType="2"/>
<ITEM CheckResult="-1" File="wmpnetwk.exe" RemoteHost="" RemotePort="0" LocalPort="5004" PortType="2"/>
<ITEM CheckResult="-1" File="wmpnetwk.exe" RemoteHost="" RemotePort="0" LocalPort="5005" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="5355" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="50459" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="50461" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="50462" PortType="2"/>
<ITEM IsPE="1" Ver="1.1.32.25147" OFN="Avira.OE.ServiceHost.exe" Product="Avira.OE.ServiceHost" Vendor="Avira Operations GmbH & Co. KG" MD5="ABDAEBEB09E98D13D765A0C57F3FAF88" ChangeDate="12.02.2015 14:00:08" CreateDate="12.02.2015 14:00:08" Attr="rsAh" Size="184056" CheckResult="-1" File="c:\program files (x86)\avira\my avira\avira.oe.servicehost.exe" RemoteHost="" RemotePort="0" LocalPort="50471" PortType="2"/>
<ITEM IsPE="1" Ver="1.1.32.25159" OFN="Avira.OE.Systray.exe" Product="Avira.OE.Systray" Vendor="Avira Operations GmbH & Co. KG" MD5="8CB85437667AEDBD8497D2CA85F4A17A" ChangeDate="12.02.2015 14:00:14" CreateDate="12.02.2015 14:00:14" Attr="rsAh" Size="127792" CheckResult="-1" File="c:\program files (x86)\avira\my avira\avira.oe.systray.exe" RemoteHost="" RemotePort="0" LocalPort="50473" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="51252" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="57850" PortType="2"/>
<ITEM IsPE="1" Ver="6.1.7600.16385" OFN="svchost.exe.mui" Product="Betriebssystem Microsoft® Windows®" Vendor="Microsoft Corporation" MD5="54A47F6B5E09A77E61649109C6A08866" ChangeDate="14.07.2009 02:14:41" CreateDate="14.07.2009 00:19:28" Attr="rsAh" Size="20992" CheckResult="0" File="C:\Windows\system32\svchost.exe" RemoteHost="" RemotePort="0" LocalPort="57851" PortType="2"/>
</PORTS>
<DPF> </DPF>
<CPL> </CPL>
<ActiveSetup> </ActiveSetup>
<HOSTS> </HOSTS>
-<ProtocolExt>
<ITEM LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="Microsoft .NET Runtime Execution Engine" CheckResult="-1" File="mscoree.dll" Enabled="1" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/octet-stream"/>
<ITEM LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="Microsoft .NET Runtime Execution Engine" CheckResult="-1" File="mscoree.dll" Enabled="1" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/x-complus"/>
<ITEM LegalCopyright="© Microsoft Corporation. All rights reserved." Descr="Microsoft .NET Runtime Execution Engine" CheckResult="-1" File="mscoree.dll" Enabled="1" CLSID="{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" RegKey="SOFTWARE\Classes\PROTOCOLS\Filter\application/x-msdownload"/>
</ProtocolExt>
-<NET_SHARE>
<ITEM Name="ADMIN$" Connections="0" Path="C:\Windows"/>
<ITEM Name="C$" Connections="0" Path="C:\"/>
<ITEM Name="IPC$" Connections="0" Path=""/>
<ITEM Name="Q$" Connections="0" Path="Q:\"/>
<ITEM Name="Users" Connections="0" Path="C:\Users"/>
</NET_SHARE>
-<WMI_INFO>
-<SecurityCenter>
<AntiVirusProduct> </AntiVirusProduct>
<FireWallProduct> </FireWallProduct>
</SecurityCenter>
-<SecurityCenter2>
-<AntiVirusProduct>
<Data Name="Avira Desktop" ProductState="262144" pathToSignedProductExe="C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe"/>
</AntiVirusProduct>
<FireWallProduct> </FireWallProduct>
-<AntiSpywareProduct>
<Data Name="Avira Desktop" ProductState="262144" pathToSignedProductExe="C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe"/>
<Data Name="Windows Defender" ProductState="397568" pathToSignedProductExe="%ProgramFiles%\Windows Defender\MSASCui.exe"/>
</AntiSpywareProduct>
</SecurityCenter2>
</WMI_INFO>
-<NET_DIAG>
-<DNS>
<Host Name="yandex.ru" PingInfo="0,82,213.180.193.11" Ping="1" IP="213.180.193.11,93.158.134.11,87.250.250.11,213.180.204.11"/>
<Host Name="google.ru" PingInfo="0,35,173.194.44.87" Ping="1" IP="173.194.44.87,173.194.44.88,173.194.44.79,173.194.44.95"/>
<Host Name="google.com" PingInfo="0,38,173.194.44.73" Ping="1" IP="173.194.44.73,173.194.44.78,173.194.44.68,173.194.44.65,173.194.44.69,173.194.44.66,173.194.44.72,173.194.44.64,173.194.44.71,173.194.44.67,173.194.44.70"/>
<Host Name="www.kaspersky.com" PingInfo="0,24,195.27.252.18" Ping="1" IP="195.27.252.18"/>
<Host Name="www.kaspersky.ru" PingInfo="0,26,195.27.252.110" Ping="1" IP="195.27.252.110"/>
<Host Name="dnl-03.geo.kaspersky.com" PingInfo="0,33,195.122.169.18" Ping="1" IP="195.122.169.18"/>
<Host Name="dnl-11.geo.kaspersky.com" PingInfo="0,25,80.239.197.103" Ping="1" IP="80.239.197.103"/>
<Host Name="activation-v2.kaspersky.com" PingInfo="11010,0,0.0.0.0" Ping="0" IP="195.27.252.50"/>
<Host Name="odnoklassniki.ru" PingInfo="0,85,217.20.147.94" Ping="1" IP="217.20.147.94"/>
<Host Name="vk.com" PingInfo="0,71,87.240.131.119" Ping="1" IP="87.240.131.119,87.240.131.118,87.240.131.117"/>
<Host Name="vkontakte.ru" PingInfo="0,70,95.213.4.242" Ping="1" IP="95.213.4.242,95.213.4.243,95.213.4.244"/>
<Host Name="twitter.com" PingInfo="0,124,185.45.5.32" Ping="1" IP="185.45.5.32,185.45.5.43"/>
<Host Name="facebook.com" PingInfo="0,127,173.252.120.6" Ping="1" IP="173.252.120.6"/>
<Host Name="ru-ru.facebook.com" PingInfo="0,24,31.13.93.3" Ping="1" IP="31.13.93.3"/>
</DNS>
-<IE_Setup>
<Key Name="AutoConfigURL" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="AutoConfigProxy" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL="wininet.dll"/>
<Key Name="ProxyOverride" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="ProxyServer" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="" RegKey="HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies" VAL=""/>
</IE_Setup>
<TCP_IP> </TCP_IP>
<TCP_IP_PR> </TCP_IP_PR>
</NET_DIAG>
-<WMI_INFO>
-<SecurityCenter>
<AntiVirusProduct> </AntiVirusProduct>
<FireWallProduct> </FireWallProduct>
</SecurityCenter>
-<SecurityCenter2>
-<AntiVirusProduct>
<Data Name="Avira Desktop" ProductState="262144" pathToSignedProductExe="C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe"/>
</AntiVirusProduct>
<FireWallProduct> </FireWallProduct>
-<AntiSpywareProduct>
<Data Name="Avira Desktop" ProductState="262144" pathToSignedProductExe="C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe"/>
<Data Name="Windows Defender" ProductState="397568" pathToSignedProductExe="%ProgramFiles%\Windows Defender\MSASCui.exe"/>
</AntiSpywareProduct>
</SecurityCenter2>
</WMI_INFO>
-<NET_DIAG>
-<DNS>
<Host Name="yandex.ru" PingInfo="0,80,213.180.193.11" Ping="1" IP="213.180.193.11,93.158.134.11,213.180.204.11,87.250.250.11"/>
<Host Name="google.ru" PingInfo="0,39,173.194.44.88" Ping="1" IP="173.194.44.88,173.194.44.79,173.194.44.95,173.194.44.87"/>
<Host Name="google.com" PingInfo="0,37,173.194.44.71" Ping="1" IP="173.194.44.71,173.194.44.65,173.194.44.72,173.194.44.66,173.194.44.70,173.194.44.67,173.194.44.64,173.194.44.68,173.194.44.69,173.194.44.78,173.194.44.73"/>
<Host Name="www.kaspersky.com" PingInfo="0,27,195.27.252.18" Ping="1" IP="195.27.252.18"/>
<Host Name="www.kaspersky.ru" PingInfo="0,25,195.27.252.110" Ping="1" IP="195.27.252.110"/>
<Host Name="dnl-03.geo.kaspersky.com" PingInfo="0,34,212.73.221.202" Ping="1" IP="212.73.221.202"/>
<Host Name="dnl-11.geo.kaspersky.com" PingInfo="0,24,80.239.169.132" Ping="1" IP="80.239.169.132"/>
<Host Name="activation-v2.kaspersky.com" PingInfo="11010,0,0.0.0.0" Ping="0" IP="195.27.252.50"/>
<Host Name="odnoklassniki.ru" PingInfo="0,76,217.20.147.94" Ping="1" IP="217.20.147.94"/>
<Host Name="vk.com" PingInfo="0,62,87.240.131.99" Ping="1" IP="87.240.131.99,87.240.131.97,87.240.131.120"/>
<Host Name="vkontakte.ru" PingInfo="0,69,95.213.4.242" Ping="1" IP="95.213.4.242,95.213.4.241,95.213.4.248"/>
<Host Name="twitter.com" PingInfo="0,128,185.45.5.43" Ping="1" IP="185.45.5.43,185.45.5.32"/>
<Host Name="facebook.com" PingInfo="0,157,173.252.120.6" Ping="1" IP="173.252.120.6"/>
<Host Name="ru-ru.facebook.com" PingInfo="0,25,31.13.93.3" Ping="1" IP="31.13.93.3"/>
</DNS>
-<IE_Setup>
<Key Name="AutoConfigURL" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="AutoConfigProxy" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL="wininet.dll"/>
<Key Name="ProxyOverride" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="ProxyServer" RegKey="HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" VAL=""/>
<Key Name="" RegKey="HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies" VAL=""/>
</IE_Setup>
<TCP_IP> </TCP_IP>
<TCP_IP_PR> </TCP_IP_PR>
</NET_DIAG>
-<IPU>
<ITEM X2="Remotedesktopdienste" X1="TermService" Code="1"/>
<ITEM X2="SSDP-Suche" X1="SSDPSRV" Code="1"/>
<ITEM X2="Aufgabenplanung" X1="Schedule" Code="1"/>
<ITEM Code="2"/>
<ITEM Code="3"/>
<ITEM Code="5"/>
<ITEM X1="1" Code="8"/>
<ITEM X2="Remotedesktopdienste" X1="TermService" Code="1"/>
<ITEM X2="SSDP-Suche" X1="SSDPSRV" Code="1"/>
<ITEM X2="Aufgabenplanung" X1="Schedule" Code="1"/>
<ITEM Code="2"/>
<ITEM Code="3"/>
<ITEM Code="5"/>
<ITEM X1="1" Code="8"/>
</IPU>
-<WIZARD-TSW>
<ITEM Fixed="0" Level="3" ID="58"/>
<ITEM Fixed="0" Level="3" ID="59"/>
<ITEM Fixed="0" Level="2" ID="61"/>
</WIZARD-TSW> |