Загрузка данных


Startup\	mod
          .lnk	10.0.18362.1	Microsoft Corporation		Auto	C:\Windows\SysWOW64\rundll32.exe	2019-03-19 07:45.32	61,952	add
Services\	mod
Клиент групповой политики	10.0.18362.1	Microsoft Corporation		Auto	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation	Run	Auto	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	new
Контейнер службы Microsoft Passport	10.0.18362.1	Microsoft Corporation	Run	Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation		Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	new
Служба диспетчера доступа к возможностям	10.0.18362.1	Microsoft Corporation	Run	Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation		Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	new
Служба лицензий клиента (ClipSVC)	10.0.18362.1	Microsoft Corporation	Run	Manual	C:\Windows\System32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation		Manual	C:\Windows\System32\svchost.exe	2019-03-19 07:44.33	53,744	new
Служба развертывания AppX (AppXSVC)	10.0.18362.1	Microsoft Corporation	Run	Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation		Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	new
Центр обновления Windows	10.0.18362.1	Microsoft Corporation	Run	Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	old
	10.0.18362.1	Microsoft Corporation		Manual	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	new
Running Processes\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	C:\Windows\system32\wbem\wmiprvse.exe	2019-03-19 07:44.00	483,840	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	C:\Windows\system32\wbem\wmiprvse.exe	2019-03-19 07:44.00	483,840	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	C:\Windows\SysWOW64\rundll32.exe	2019-03-19 07:45.32	61,952	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	C:\Windows\System32\smartscreen.exe	2019-03-19 07:44.03	2,759,680	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	C:\Windows\system32\svchost.exe	2019-03-19 07:44.33	53,744	del
Running Processes\Explorer.EXE\	mod
Internet Explorer	11.0.18362.1	Microsoft Corporation	c:\windows\system32\msiso.dll	2019-03-19 07:44.50	308,736	add
Microsoft® Windows® Operating System	10.0.18362.113	Microsoft Corporation	c:\windows\system32\cryptdll.dll	2019-06-12 04:33.42	66,360	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\execmodelproxy.dll	2019-03-19 07:44.03	83,456	add
Microsoft® Windows® Operating System	4.18.1901.16384	Microsoft Corporation	c:\windows\system32\securityhealthproxystub.dll	2019-03-19 07:44.39	106,296	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\storageusage.dll	2019-06-12 04:33.50	130,560	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.cloudstore.schema.shell.dll	2019-03-19 07:43.57	1,113,088	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\authui.dll	2019-03-19 07:44.00	261,120	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\capauthz.dll	2019-03-19 07:44.01	313,016	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ehstorapi.dll	2019-03-19 07:45.38	132,096	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\execmodelclient.dll	2019-03-19 07:44.03	318,176	add
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\windows.internal.shell.broker.dll	2019-06-12 04:33.44	888,056	add
Служба Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\tquery.dll	2019-03-19 07:44.11	3,263,488	add
Running Processes\Explorer.EXE\Opened Handles\	mod
		File	\Device\CNG			del
		File	\Device\DeviceApi			del
		File	\Device\KsecDD			del
		File	\Device\Nsi			del
		File	\Device\WMIDataDevice			del
		File	\FileSystem\Filters\FltMgrMsg			del
		Directory	\KnownDlls			del
		Directory	\Sessions\1\BaseNamedObjects			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Program Files\Windows Defender\ru-RU\shellext.dll.mui	2023-06-12 02:28.21	13,720	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\acppage.dll.mui	2023-06-12 02:28.22	27,040	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ActionCenter.dll.mui	2023-06-12 02:28.22	59,296	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ApplicationFrame.dll.mui	2023-06-12 02:28.22	13,720	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bthprops.cpl.mui	2023-06-12 02:28.22	27,544	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dui70.dll.mui	2023-06-12 02:28.22	15,248	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui	2023-06-12 02:28.22	37,792	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\hcproviders.dll.mui	2023-06-12 02:28.23	17,824	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\InputSwitch.dll.mui	2023-06-12 02:28.23	18,848	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mpr.dll.mui	2023-06-12 02:28.23	12,704	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui	2023-06-12 02:28.23	30,616	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnidui.dll.mui	2023-06-12 02:28.23	18,840	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\sndvolsso.dll.mui	2023-06-12 02:28.24	17,312	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\stobject.dll.mui	2023-06-12 02:28.24	18,848	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twext.dll.mui	2023-06-12 02:28.24	16,280	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinui.pcshell.dll.mui	2023-06-12 02:28.24	16,288	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIRibbon.dll.mui	2023-06-12 02:28.24	50,056	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui	2023-06-12 02:28.24	29,576	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui	2023-06-12 02:28.24	78,240	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wscui.cpl.mui	2023-06-12 02:28.25	98,200	del
		Directory	C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe			del
		Directory	C:\ProgramData\Microsoft\Windows\Start Menu			del
		Directory	C:\ProgramData\Microsoft\Windows\Start Menu\Programs			del
		Directory	C:\ProgramData\Microsoft\Windows\WER\ReportArchive			del
		Directory	C:\Users\Public\Desktop			del
		Directory	C:\Users\user\AppData\Local\Microsoft\GameDVR			del
		File	C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin	2026-10-05 20:31.00	1,848,932	del
		Directory	C:\Users\user\AppData\Local\Microsoft\Windows\Burn			del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db	2023-06-12 15:55.27	1,048,576	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db	2026-10-05 20:34.56	2,097,152	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db	2026-10-06 02:42.01	4,194,304	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db	2026-10-05 21:58.11	116,496	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db	2023-06-12 15:55.30	1,048,576	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db	2023-06-12 15:55.30	1,048,576	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db	2023-06-12 15:55.30	1,048,576	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db	2023-06-12 15:55.30	1,048,576	del
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db	2023-09-08 11:07.24	29,232	del
		Directory	C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC			del
		Directory	C:\Users\user\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu			del
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs			del
		Directory	C:\Users\user\Desktop			del
		Directory	C:\Users\user\Desktop\lab1			del
		Directory	C:\Users\user\Desktop\lab1\src			del
		Directory	C:\Users\user\Documents			del
		Directory	C:\Users\user\Downloads			del
		Directory	C:\Users\user\Pictures			del
		Directory	C:\Windows\bcastdvr			del
		File	C:\Windows\Fonts\segoeui.ttf	2019-03-19 07:44.11	955,804	del
		File	C:\Windows\Fonts\StaticCache.dat	2019-06-12 04:33.43	19,333,120	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		File	C:\Windows\ru-RU\explorer.exe.mui	2019-03-19 14:34.27	14,848	del
		Directory	C:\Windows\System32			del
		File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	del
		File	C:\Windows\System32\ru-RU\dsreg.dll.mui	2019-06-12 04:33.59	47,104	del
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
		File	C:\Windows\System32\ru-RU\ole32.dll.mui	2019-03-19 14:34.30	31,232	del
		File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	del
		File	C:\Windows\System32\WinMetadata\Windows.UI.winmd	2019-03-19 07:45.02	654,288	del
		File	C:\Windows\SystemResources\ExplorerFrame.dll.mun	2019-03-19 07:45.05	2,640,896	del
		File	C:\Windows\SystemResources\imageres.dll.mun	2019-03-19 07:43.55	22,571,008	del
		File	C:\Windows\SystemResources\shell32.dll.mun	2019-06-12 04:33.41	14,768,128	del
		File	C:\Windows\SystemResources\SndVolSSO.dll.mun	2019-03-19 07:44.28	587,776	del
		File	C:\Windows\SystemResources\stobject.dll.mun	2019-03-19 07:43.55	132,608	del
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9			del
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{1f3427c8-5c10-4210-aa03-2ee45287d668}\Instance			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\Instance			del
		Key	HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance			del
		Key	HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{0D7AC4D6-88C0-42F4-9352-237C536DA832}			del
		Key	HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{CDE990B0-E58E-4B56-9042-3691614CF4D0}			del
		Key	HKLM\SOFTWARE\Classes\PackagedCom			del
		Key	HKLM\SOFTWARE\Classes\PackagedCom\ClassIndex			del
		Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			del
		Key	HKLM\SOFTWARE\Microsoft\IdentityStore\Providers			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			del
		Key	HKLM\SOFTWARE\Microsoft\KGL\OneSettings			del
		Key	HKLM\SOFTWARE\Microsoft\MSF\Registration\Listen			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\PlayToReceiver			del
		Key	HKLM\SOFTWARE\Microsoft\Security Center			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			del
		Key	HKLM\SOFTWARE\Microsoft\TabletTip\1.7			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.help			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.newfolder			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.properties			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.redo			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.rename			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.RibbonDelete			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.undo			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PerceptionSimulationExtensions			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\Shell			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			del
		Key	HKLM\SOFTWARE\Policies			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\WOW6432Node			del
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder			del
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder			del
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkUxManager			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			del
		Key	HKU			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Colors			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Desktop			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Keyboard			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\GameBar			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\MSF\Registration\Listen			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\TabletTip\1.7			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollection\Current			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollectionlocal\Current			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstarttilepropertiesmap\Current			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstartvolatiletilepropertiesmap\Current			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.roamedtilepropertiesmap\Current			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\BannerStore			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ModeTriggerCachedKey			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{BCB48336-4DDD-48FF-BB0B-D3190DACB3E2}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}\Count			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\VirtualDesktops			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\GameDVR			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Holographic			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell\Bags\1\Desktop			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\WorkFolders			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache			del
		File	\Device\CNG			add
		File	\Device\DeviceApi			add
		File	\Device\KsecDD			add
		File	\Device\Nsi			add
		File	\Device\WMIDataDevice			add
		File	\FileSystem\Filters\FltMgrMsg			add
		Directory	\KnownDlls			add
		Directory	\Sessions\1\BaseNamedObjects			add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Program Files\Windows Defender\ru-RU\shellext.dll.mui	2023-06-12 02:28.21	13,720	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\acppage.dll.mui	2023-06-12 02:28.22	27,040	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ActionCenter.dll.mui	2023-06-12 02:28.22	59,296	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ApplicationFrame.dll.mui	2023-06-12 02:28.22	13,720	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bthprops.cpl.mui	2023-06-12 02:28.22	27,544	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dui70.dll.mui	2023-06-12 02:28.22	15,248	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui	2023-06-12 02:28.22	37,792	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\hcproviders.dll.mui	2023-06-12 02:28.23	17,824	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\InputSwitch.dll.mui	2023-06-12 02:28.23	18,848	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mpr.dll.mui	2023-06-12 02:28.23	12,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui	2023-06-12 02:28.23	30,616	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnidui.dll.mui	2023-06-12 02:28.23	18,840	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\sndvolsso.dll.mui	2023-06-12 02:28.24	17,312	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\stobject.dll.mui	2023-06-12 02:28.24	18,848	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twext.dll.mui	2023-06-12 02:28.24	16,280	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinui.pcshell.dll.mui	2023-06-12 02:28.24	16,288	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIRibbon.dll.mui	2023-06-12 02:28.24	50,056	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui	2023-06-12 02:28.24	29,576	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui	2023-06-12 02:28.24	78,240	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wscui.cpl.mui	2023-06-12 02:28.25	98,200	add
		Directory	C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe			add
		Directory	C:\ProgramData\Microsoft\Windows\Start Menu			add
		Directory	C:\ProgramData\Microsoft\Windows\Start Menu\Programs			add
		Directory	C:\ProgramData\Microsoft\Windows\WER\ReportArchive			add
		Directory	C:\Users\Public\Desktop			add
		Directory	C:\Users\user\AppData\Local\Microsoft\GameDVR			add
		File	C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin	2026-10-05 20:31.00	1,848,932	add
		Directory	C:\Users\user\AppData\Local\Microsoft\Windows\Burn			add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db	2023-06-12 15:55.27	1,048,576	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db	2026-10-05 20:34.56	2,097,152	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db	2026-10-06 02:42.01	4,194,304	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db	2026-10-05 21:58.11	116,496	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db	2023-06-12 15:55.30	1,048,576	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db	2023-06-12 15:55.30	1,048,576	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db	2023-06-12 15:55.30	1,048,576	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db	2023-06-12 15:55.30	1,048,576	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db	2023-09-08 11:07.24	29,232	add
		Directory	C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC			add
		Directory	C:\Users\user\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu			add
		Directory	C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs			add
		Directory	C:\Users\user\Desktop			add
		Directory	C:\Users\user\Desktop\lab1			add
		Directory	C:\Users\user\Desktop\lab1\src			add
		Directory	C:\Users\user\Documents			add
		Directory	C:\Users\user\Downloads			add
		Directory	C:\Users\user\Pictures			add
		Directory	C:\Windows\bcastdvr			add
		File	C:\Windows\Fonts\segoeui.ttf	2019-03-19 07:44.11	955,804	add
		File	C:\Windows\Fonts\StaticCache.dat	2019-06-12 04:33.43	19,333,120	add
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	add
		File	C:\Windows\ru-RU\explorer.exe.mui	2019-03-19 14:34.27	14,848	add
		Directory	C:\Windows\System32			add
		File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	add
		File	C:\Windows\System32\ru-RU\dsreg.dll.mui	2019-06-12 04:33.59	47,104	add
		File	C:\Windows\System32\ru-RU\ieframe.dll.mui	2019-03-19 14:34.16	1,805,824	add
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	add
		File	C:\Windows\System32\ru-RU\ole32.dll.mui	2019-03-19 14:34.30	31,232	add
		File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	add
		File	C:\Windows\System32\WinMetadata\Windows.UI.winmd	2019-03-19 07:45.02	654,288	add
		File	C:\Windows\SystemResources\ExplorerFrame.dll.mun	2019-03-19 07:45.05	2,640,896	add
		File	C:\Windows\SystemResources\imageres.dll.mun	2019-03-19 07:43.55	22,571,008	add
		File	C:\Windows\SystemResources\shell32.dll.mun	2019-06-12 04:33.41	14,768,128	add
		File	C:\Windows\SystemResources\SndVolSSO.dll.mun	2019-03-19 07:44.28	587,776	add
		File	C:\Windows\SystemResources\stobject.dll.mun	2019-03-19 07:43.55	132,608	add
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9			add
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97			add
		Key	HKLM			add
		Key	HKLM\SOFTWARE			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{1f3427c8-5c10-4210-aa03-2ee45287d668}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance			add
		Key	HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{0D7AC4D6-88C0-42F4-9352-237C536DA832}			add
		Key	HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{CDE990B0-E58E-4B56-9042-3691614CF4D0}			add
		Key	HKLM\SOFTWARE\Classes\PackagedCom			add
		Key	HKLM\SOFTWARE\Classes\PackagedCom\ClassIndex			add
		Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			add
		Key	HKLM\SOFTWARE\Microsoft\IdentityStore\Providers			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			add
		Key	HKLM\SOFTWARE\Microsoft\KGL\OneSettings			add
		Key	HKLM\SOFTWARE\Microsoft\MSF\Registration\Listen			add
		Key	HKLM\SOFTWARE\Microsoft\Ole			add
		Key	HKLM\SOFTWARE\Microsoft\PlayToReceiver			add
		Key	HKLM\SOFTWARE\Microsoft\Security Center			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			add
		Key	HKLM\SOFTWARE\Microsoft\TabletTip\1.7			add
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
		Key	HKLM\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.help			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.newfolder			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.properties			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.redo			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.rename			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.RibbonDelete			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.undo			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PerceptionSimulationExtensions			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\Shell			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			add
		Key	HKLM\SOFTWARE\Policies			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\WOW6432Node			add
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder			add
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder			add
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkUxManager			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			add
		Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			add
		Key	HKU			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Colors			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Desktop			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Keyboard			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\GameBar			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\MSF\Registration\Listen			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\TabletTip\1.7			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollection\Current			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollectionlocal\Current			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstarttilepropertiesmap\Current			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstartvolatiletilepropertiesmap\Current			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.roamedtilepropertiesmap\Current			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\BannerStore			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ModeTriggerCachedKey			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{BCB48336-4DDD-48FF-BB0B-D3190DACB3E2}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}\Count			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\VirtualDesktops			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\GameDVR			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Holographic			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell\Bags\1\Desktop			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\WorkFolders			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache			add
Running Processes\lsass.exe\Opened Handles\	mod
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msprivs.dll.mui	2023-06-12 02:28.23	15,776	add
Running Processes\MicrosoftEdge.exe -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca\Opened Handles\	mod
		File	C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\~DF39C635ED25EB69E3.TMP	2026-10-07 02:08.29	0	old
		File	C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\~DF39C635ED25EB69E3.TMP	2026-10-07 02:08.45	16,384	new
Running Processes\ProcessHacker.exe\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dbgcore.dll	2019-03-19 07:44.35	157,696	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dbghelp.dll	2019-03-19 07:44.35	1,930,752	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\apphelp.dll	2019-03-19 07:44.28	564,736	add
Running Processes\ProcessHacker.exe\Opened Handles\	mod
		File	C:\Windows\System32\ru-RU\ntdll.dll.mui	2019-03-19 14:34.30	484,864	add
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d			add
		File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui	2019-06-12 04:33.42	12,288	add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion			add
Running Processes\Procmon64.exe\	mod
Internet Explorer	11.0.18362.175	Microsoft Corporation	c:\windows\system32\urlmon.dll	2019-06-12 04:33.44	1,853,440	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47langs.dll	2019-03-19 07:44.15	369,504	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47mrm.dll	2019-03-19 07:44.15	186,672	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cldapi.dll	2019-03-19 07:44.28	105,984	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coml2.dll	2019-03-19 07:44.15	477,240	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptbase.dll	2019-03-19 07:44.36	33,848	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\duser.dll	2019-03-19 07:44.47	578,560	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\globinputhost.dll	2019-03-19 07:44.15	130,560	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\linkinfo.dll	2019-03-19 07:44.30	30,720	add
Microsoft® Windows® Operating System	7.2.18362.1	Microsoft Corporation	c:\windows\system32\oleacc.dll	2019-03-19 07:45.00	395,776	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sspicli.dll	2019-03-19 07:44.36	179,944	add
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\windows.globalization.dll	2019-06-12 04:33.37	1,784,832	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositoryps.dll	2019-03-19 07:44.15	1,274,336	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.storage.search.dll	2019-03-19 07:44.04	748,544	add
Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\structuredquery.dll	2019-03-19 07:44.15	676,840	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\program files\common files\microsoft shared\ink\tiptsf.dll	2019-03-19 07:45.49	659,464	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dui70.dll	2019-03-19 07:44.47	1,748,992	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\edputil.dll	2019-03-19 07:44.47	119,808	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ehstorshell.dll	2019-03-19 07:44.47	208,384	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\explorerframe.dll	2019-03-19 07:45.05	2,094,592	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\networkexplorer.dll	2019-03-19 07:44.48	76,288	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\setupapi.dll	2019-03-19 07:45.00	4,683,784	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\twinapi.dll	2019-03-19 07:44.33	636,416	add
Running Processes\Procmon64.exe\Opened Handles\	mod
		File	\FileSystem\Filters\FltMgrMsg			add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc.dll.mui	2023-06-12 02:28.22	13,216	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc6.dll.mui	2023-06-12 02:28.22	39,832	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui	2023-06-12 02:28.22	37,792	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\napinsp.dll.mui	2023-06-12 02:28.23	13,216	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui	2023-06-12 02:28.23	30,616	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnrpnsp.dll.mui	2023-06-12 02:28.23	13,208	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wship6.dll.mui	2023-06-12 02:28.25	13,216	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshqos.dll.mui	2023-06-12 02:28.25	13,216	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshtcpip.dll.mui	2023-06-12 02:28.25	13,216	add
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db	2023-06-12 15:55.27	1,048,576	add
		Directory	C:\Users\user\Desktop\tools\ProcessMonitor			old
		Directory	C:\Users\user\Desktop\tools\ProcessMonitor			new
		File	C:\Windows\SystemResources\comdlg32.dll.mun	2019-03-19 07:45.05	352,768	add
		File	C:\Windows\SystemResources\ExplorerFrame.dll.mun	2019-03-19 07:45.05	2,640,896	add
		File	C:\Windows\SystemResources\shell32.dll.mun	2019-06-12 04:33.41	14,768,128	add
		Key	HKLM\SOFTWARE			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{088e3905-0323-4b02-9826-5d99428e115f}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{24ad3ad4-a569-4530-98e1-ab02f9417aa8}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{d3162b92-9365-467a-956b-92703aca08af}\Instance			add
		Key	HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\Shell			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			add
		Key	HKLM\SOFTWARE\Policies			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\WOW6432Node			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell			add
Running Processes\rundll32.exe {638125B9-A355-4093-ADB2-B0299E77A4DB}.dbf, #1 #1\	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64.dll	2019-03-19 07:44.38	335,752	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64cpu.dll	2019-03-19 07:44.38	20,728	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64win.dll	2019-03-19 07:44.38	510,488	add
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	add
Running Processes\rundll32.exe {638125B9-A355-4093-ADB2-B0299E77A4DB}.dbf, #1 #1\Opened Handles\	add
		File	\Device\CNG			add
		File	\Device\DeviceApi			add
		File	\Device\KsecDD			add
		File	\Device\Nsi			add
		Directory	\KnownDlls			add
		Directory	\KnownDlls32			add
		Directory	\Sessions\1\BaseNamedObjects			add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rundll32.exe.mui	2023-06-12 02:28.24	13,208	add
		Directory	C:\Users\user\AppData\Roaming\Microsoft			add
		Directory	C:\Windows			add
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	add
		Key	HKLM			add
		Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			add
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			add
		Key	HKLM\SOFTWARE\Microsoft\Ole			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			add
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			add
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
		Key	HKLM\SOFTWARE\Policies			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\WOW6432Node			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder			add
		Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			add
		Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			add
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5			add
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9			add
		Key	HKU			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			add
Running Processes\RuntimeBroker.exe -Embedding\	mod
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\appresolver.dll	2019-03-19 07:44.21	558,344	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\slc.dll	2019-03-19 07:44.32	140,800	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sppc.dll	2019-03-19 07:44.32	136,192	del
Running Processes\RuntimeBroker.exe -Embedding\	mod
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\iertutil.dll	2019-06-12 04:33.44	2,769,976	add
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\wininet.dll	2019-06-12 04:33.43	5,040,640	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47langs.dll	2019-03-19 07:44.15	369,504	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cfgmgr32.dll	2019-03-19 07:44.35	293,344	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coml2.dll	2019-03-19 07:44.15	477,240	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptsp.dll	2019-03-19 07:44.33	80,112	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\d3d11.dll	2019-03-19 07:44.11	2,466,296	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dxcore.dll	2019-03-19 07:44.06	112,296	add
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\dxgi.dll	2019-06-12 04:33.38	939,504	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\linkinfo.dll	2019-03-19 07:44.30	30,720	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\profapi.dll	2019-03-19 07:44.36	110,280	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\secur32.dll	2019-03-19 07:45.00	27,648	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositorycore.dll	2019-03-19 07:44.15	45,568	add
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	del
Windows Installer - Unicode	5.0.18362.175	Microsoft Corporation	c:\windows\system32\msi.dll	2019-06-12 04:33.52	4,577,280	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\appresolver.dll	2019-03-19 07:44.21	558,344	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\capauthz.dll	2019-03-19 07:44.01	313,016	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mlang.dll	2019-03-19 07:44.58	245,760	add
Операционная система Microsoft® Windows®	10.0.18362.113	Microsoft Corporation	c:\windows\system32\ole32.dll	2019-06-12 04:33.40	1,395,600	add
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\shell32.dll	2019-06-12 04:33.41	7,241,800	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shlwapi.dll	2019-03-19 07:45.05	329,200	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\slc.dll	2019-03-19 07:44.32	140,800	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sppc.dll	2019-03-19 07:44.32	136,192	add
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\userenv.dll	2019-06-12 04:33.42	139,472	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\uxtheme.dll	2019-03-19 07:44.33	606,208	add
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\windows.internal.shell.broker.dll	2019-06-12 04:33.44	888,056	add
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\windows.storage.dll	2019-06-12 04:33.39	7,887,656	add
Операционная система Microsoft® Windows®	6.10.18362.175	Microsoft Corporation	c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9\comctl32.dll	2019-06-12 04:33.44	2,624,824	add
Служба Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\propsys.dll	2019-03-19 07:44.15	977,680	add
Running Processes\RuntimeBroker.exe -Embedding\Opened Handles\	mod
		File	\Device\CNG			del
		File	\Device\KsecDD			del
		Directory	\KnownDlls			del
		Directory	\Sessions\1\BaseNamedObjects			del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKU			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			del
		File	\Device\CNG			add
		File	\Device\DeviceApi			add
		File	\Device\KsecDD			add
		Directory	\KnownDlls			add
		Directory	\Sessions\1\BaseNamedObjects			add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	add
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	add
		Directory	C:\Windows\System32			add
		File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	add
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9			add
		Key	HKLM			add
		Key	HKLM\SOFTWARE			add
		Key	HKLM\SOFTWARE\Classes			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			add
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			add
		Key	HKLM\SOFTWARE\Microsoft\Ole			add
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			add
		Key	HKLM\SOFTWARE\Policies			add
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKLM\SOFTWARE\WOW6432Node			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			add
		Key	HKU			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			add
Running Processes\RuntimeBroker.exe -Embedding\	mod
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\iertutil.dll	2019-06-12 04:33.44	2,769,976	del
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\wininet.dll	2019-06-12 04:33.43	5,040,640	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47langs.dll	2019-03-19 07:44.15	369,504	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cfgmgr32.dll	2019-03-19 07:44.35	293,344	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coml2.dll	2019-03-19 07:44.15	477,240	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptsp.dll	2019-03-19 07:44.33	80,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\d3d11.dll	2019-03-19 07:44.11	2,466,296	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dxcore.dll	2019-03-19 07:44.06	112,296	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\dxgi.dll	2019-06-12 04:33.38	939,504	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\linkinfo.dll	2019-03-19 07:44.30	30,720	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\profapi.dll	2019-03-19 07:44.36	110,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\secur32.dll	2019-03-19 07:45.00	27,648	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositorycore.dll	2019-03-19 07:44.15	45,568	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	add
Windows Installer - Unicode	5.0.18362.175	Microsoft Corporation	c:\windows\system32\msi.dll	2019-06-12 04:33.52	4,577,280	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\appresolver.dll	2019-03-19 07:44.21	558,344	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\capauthz.dll	2019-03-19 07:44.01	313,016	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mlang.dll	2019-03-19 07:44.58	245,760	del
Операционная система Microsoft® Windows®	10.0.18362.113	Microsoft Corporation	c:\windows\system32\ole32.dll	2019-06-12 04:33.40	1,395,600	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\shell32.dll	2019-06-12 04:33.41	7,241,800	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shlwapi.dll	2019-03-19 07:45.05	329,200	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\slc.dll	2019-03-19 07:44.32	140,800	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sppc.dll	2019-03-19 07:44.32	136,192	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\userenv.dll	2019-06-12 04:33.42	139,472	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\uxtheme.dll	2019-03-19 07:44.33	606,208	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\windows.internal.shell.broker.dll	2019-06-12 04:33.44	888,056	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\windows.storage.dll	2019-06-12 04:33.39	7,887,656	del
Операционная система Microsoft® Windows®	6.10.18362.175	Microsoft Corporation	c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9\comctl32.dll	2019-06-12 04:33.44	2,624,824	del
Служба Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\propsys.dll	2019-03-19 07:44.15	977,680	del
Running Processes\RuntimeBroker.exe -Embedding\Opened Handles\	mod
		File	\Device\CNG			add
		File	\Device\KsecDD			add
		Directory	\KnownDlls			add
		Directory	\Sessions\1\BaseNamedObjects			add
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	add
		Directory	C:\Windows\System32			add
		Key	HKLM			add
		Key	HKLM\SOFTWARE\Classes			add
		Key	HKLM\SOFTWARE\Microsoft\Ole			add
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			add
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			add
		Key	HKU			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			add
		File	\Device\CNG			del
		File	\Device\DeviceApi			del
		File	\Device\KsecDD			del
		Directory	\KnownDlls			del
		Directory	\Sessions\1\BaseNamedObjects			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	del
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			del
		Key	HKLM\SOFTWARE\Policies			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\WOW6432Node			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKU			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			del
Running Processes\SearchIndexer.exe /Embedding\Opened Handles\	mod
		File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx	2026-10-07 02:08.29	1,048,576	old
		File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx	2026-10-07 02:08.30	1,048,576	new
		File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr	2026-10-07 02:04.48	10,574	old
		File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr	2026-10-07 02:04.48	36,678	new
Running Processes\sihost.exe\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositoryps.dll	2019-03-19 07:44.15	1,274,336	del
Running Processes\smartscreen.exe -Embedding\	del
International Components for Unicode	63.1.0.0	The ICU Project	c:\windows\system32\icu.dll	2019-06-12 04:33.39	2,321,408	del
International Components for Unicode	63.1.0.0	The ICU Project	c:\windows\system32\icuin.dll	2019-03-19 07:44.15	25,088	del
International Components for Unicode	63.1.0.0	The ICU Project	c:\windows\system32\icuuc.dll	2019-03-19 07:44.15	29,696	del
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\iertutil.dll	2019-06-12 04:33.44	2,769,976	del
Internet Explorer	11.0.18362.175	Microsoft Corporation	c:\windows\system32\urlmon.dll	2019-06-12 04:33.44	1,853,440	del
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\wininet.dll	2019-06-12 04:33.43	5,040,640	del
Microsoft ® Chakra	11.0.18362.175	Microsoft Corporation	c:\windows\system32\chakra.dll	2019-06-12 04:33.52	7,757,312	del
Microsoft® .NET Framework	4.8.3673.0	Microsoft Corporation	c:\windows\system32\rometadata.dll	2019-03-19 07:44.06	234,432	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptbase.dll	2019-03-19 07:44.36	33,848	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptnet.dll	2019-03-19 07:44.33	168,448	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptsp.dll	2019-03-19 07:44.33	80,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dpapi.dll	2019-03-19 07:44.35	15,872	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dsparse.dll	2019-03-19 07:44.35	30,208	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\fwbase.dll	2019-03-19 07:44.15	162,304	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\imagehlp.dll	2019-03-19 07:44.35	108,936	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\imm32.dll	2019-03-19 07:44.38	176,360	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncryptsslp.dll	2019-03-19 07:44.35	134,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\netutils.dll	2019-03-19 07:44.35	40,784	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\nsi.dll	2019-03-19 07:44.36	25,000	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ntasn1.dll	2019-03-19 07:44.35	241,128	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\oleaut32.dll	2019-06-12 04:33.42	797,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ondemandconnroutehelper.dll	2019-03-19 07:44.00	73,216	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\profapi.dll	2019-03-19 07:44.36	110,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rasadhlp.dll	2019-03-19 07:45.02	16,896	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rsaenh.dll	2019-03-19 07:44.35	202,440	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\smartscreenps.dll	2019-03-19 07:44.03	256,000	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sspicli.dll	2019-03-19 07:44.36	179,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\tbs.dll	2019-03-19 07:43.54	48,048	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.security.authentication.onlineid.dll	2019-03-19 07:44.04	914,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winnsi.dll	2019-03-19 07:44.36	34,808	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winrttracing.dll	2019-03-19 07:44.01	189,952	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wkscli.dll	2019-03-19 07:44.35	80,600	del
umpdc.dll			c:\windows\system32\umpdc.dll	2019-03-19 07:43.49	54,960	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\advapi32.dll	2019-03-19 07:43.54	655,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcrypt.dll	2019-03-19 07:44.33	144,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certca.dll	2019-03-19 07:44.04	807,424	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certenroll.dll	2019-03-19 07:44.06	3,184,128	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dnsapi.dll	2019-03-19 07:44.33	818,888	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\firewallapi.dll	2019-03-19 07:44.15	551,936	del
Операционная система Microsoft® Windows®	10.0.18362.113	Microsoft Corporation	c:\windows\system32\fwpuclnt.dll	2019-06-12 04:33.39	467,456	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\iphlpapi.dll	2019-03-19 07:44.33	229,528	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mlang.dll	2019-03-19 07:44.58	245,760	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mskeyprotect.dll	2019-03-19 07:44.06	62,976	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mswsock.dll	2019-03-19 07:44.33	407,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncrypt.dll	2019-03-19 07:44.35	144,840	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\powrprof.dll	2019-03-19 07:44.35	291,336	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\schannel.dll	2019-06-12 04:33.42	537,088	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shcore.dll	2019-03-19 07:44.21	684,352	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shlwapi.dll	2019-03-19 07:45.05	329,200	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\uxtheme.dll	2019-03-19 07:44.33	606,208	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\windows.storage.dll	2019-06-12 04:33.39	7,887,656	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.web.http.dll	2019-03-19 07:44.01	1,498,624	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winhttp.dll	2019-03-19 07:44.35	980,248	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wintypes.dll	2019-03-19 07:44.33	1,393,960	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wldap32.dll	2019-03-19 07:44.35	402,432	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ws2_32.dll	2019-03-19 07:44.36	443,424	del
Running Processes\smartscreen.exe -Embedding\Opened Handles\	del
		File	\Device\CNG			del
		File	\Device\KsecDD			del
		File	\Device\Nsi			del
		Directory	\KnownDlls			del
		Directory	\Sessions\1\BaseNamedObjects			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\smartscreen.exe.mui	2023-06-12 02:28.24	25,488	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.Http.dll.mui	2023-06-12 02:28.24	23,968	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
		File	C:\Windows\System32\WinMetadata\Windows.Foundation.winmd	2019-03-19 07:45.02	69,328	del
		Key	HKLM			del
		Key	HKLM\SOFTWARE			del
		Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SOFTWARE\Policies			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\WOW6432Node			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			del
		Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces			del
		Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces			del
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5			del
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9			del
		Key	HKU			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			del
Running Processes\svchost.exe -k appmodel -p -s camsvc\	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\capabilityaccesshandlers.dll	2019-03-19 07:44.06	65,024	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\capabilityaccessmanagerclient.dll	2019-06-12 04:33.38	226,816	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cfgmgr32.dll	2019-03-19 07:44.35	293,344	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\devobj.dll	2019-03-19 07:44.35	158,592	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\oleaut32.dll	2019-06-12 04:33.42	797,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	del
umpdc.dll			c:\windows\system32\umpdc.dll	2019-03-19 07:43.49	54,960	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\advapi32.dll	2019-03-19 07:43.54	655,144	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\audioses.dll	2019-06-12 04:33.35	1,413,704	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\capabilityaccessmanager.dll	2019-06-12 04:33.38	344,576	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mmdevapi.dll	2019-03-19 07:43.47	476,936	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\powrprof.dll	2019-03-19 07:44.35	291,336	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shcore.dll	2019-03-19 07:44.21	684,352	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wintypes.dll	2019-03-19 07:44.33	1,393,960	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wldp.dll	2019-06-12 04:33.42	161,848	del
Running Processes\svchost.exe -k appmodel -p -s camsvc\Opened Handles\	del
		Directory	\BaseNamedObjects			del
		File	\Device\CNG			del
		File	\Device\DeviceApi			del
		Directory	\KnownDlls			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui	2023-06-12 02:28.24	12,680	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKU\.DEFAULT\Software\Classes			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft			del
Running Processes\svchost.exe -k appmodel -p -s StateRepository\	mod
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wintypes.dll	2019-03-19 07:44.33	1,393,960	del
Running Processes\svchost.exe -k appmodel -p -s StateRepository\Opened Handles\	mod
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd	2026-10-07 02:05.30	7,340,032	old
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd	2026-10-07 02:14.29	7,340,032	new
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm	2026-10-07 02:04.47	32,768	old
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm	2026-10-07 02:15.37	32,768	new
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal	2026-10-07 02:04.48	8,272	old
		File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal	2026-10-07 02:14.29	0	new
Running Processes\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\onecorecommonproxystub.dll	2019-03-19 07:43.45	479,744	del
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog\Opened Handles\	mod
		File	C:\Windows\System32\winevt\Logs\microsoft-windows-diagnosis-scripted%4operational.evtx	2026-10-05 22:03.02	69,632	add
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc\	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dpapi.dll	2019-03-19 07:44.35	15,872	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\imagehlp.dll	2019-03-19 07:44.35	108,936	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ktmw32.dll	2019-03-19 07:44.53	24,576	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\netutils.dll	2019-03-19 07:44.35	40,784	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnr.dll	2019-03-19 07:44.06	617,472	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnrgidshandler.dll	2019-03-19 07:44.38	488,448	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\profapi.dll	2019-03-19 07:44.36	110,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\samcli.dll	2019-03-19 07:44.35	78,848	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\tbs.dll	2019-03-19 07:43.54	48,048	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcrypt.dll	2019-03-19 07:44.33	144,144	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnrsvc.dll	2019-03-19 07:44.06	810,496	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wldp.dll	2019-06-12 04:33.42	161,848	del
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc\Opened Handles\	del
		Directory	\BaseNamedObjects			del
		File	\Device\CNG			del
		File	\Device\KsecDD			del
		Directory	\KnownDlls			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui	2023-06-12 02:28.24	12,680	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKU\S-1-5-19\Software\Classes			del
		Key	HKU\S-1-5-19\Software\Classes\Local Settings			del
		Key	HKU\S-1-5-19\Software\Classes\Local Settings\Software\Microsoft			del
Running Processes\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	add
Running Processes\svchost.exe -k netsvcs -p -s TokenBroker\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coremessaging.dll	2019-03-19 07:44.30	859,632	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coreuicomponents.dll	2019-03-19 07:44.09	3,323,336	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\inputhost.dll	2019-03-19 07:44.12	1,052,096	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\textinputframework.dll	2019-03-19 07:44.11	642,216	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositorybroker.dll	2019-03-19 07:44.15	104,464	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.staterepositoryps.dll	2019-03-19 07:44.15	1,274,336	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.ui.dll	2019-03-19 07:44.00	1,383,648	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ntmarta.dll	2019-03-19 07:44.35	181,856	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\vaultcli.dll	2019-03-19 07:44.06	289,280	del
Running Processes\svchost.exe -k netsvcs -p -s UsoSvc\Opened Handles\	mod
		File	C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.f6523472-7654-4537-a3ef-11a4a1f3ca78.1.etl	2026-10-07 02:04.47	0	old
		File	C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.f6523472-7654-4537-a3ef-11a4a1f3ca78.1.etl	2026-10-07 02:04.47	4,096	new
Running Processes\svchost.exe -k netsvcs -p -s WpnService\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\coremessaging.dll	2019-03-19 07:44.30	859,632	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\staterepository.core.dll	2019-03-19 07:44.15	716,520	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\usermgrproxy.dll	2019-03-19 07:44.38	294,912	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.security.authentication.onlineid.dll	2019-03-19 07:44.04	914,944	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\appxdeploymentclient.dll	2019-06-12 04:33.39	909,736	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\execmodelclient.dll	2019-03-19 07:44.03	318,176	del
Running Processes\svchost.exe -k netsvcs -p -s WpnService\Opened Handles\	mod
		File	C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal	2026-10-07 01:40.40	3,687,432	old
		File	C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal	2026-10-07 02:06.46	3,720,392	new
Running Processes\svchost.exe -k netsvcs -p -s wuauserv\	del
Internet Explorer	11.0.18362.116	Microsoft Corporation	c:\windows\system32\iertutil.dll	2019-06-12 04:33.44	2,769,976	del
Microsoft XML Core Services	6.30.18362.175	Microsoft Corporation	c:\windows\system32\msxml6.dll	2019-06-12 04:33.38	2,449,456	del
Microsoft® Windows® Operating System	4.18.26080.4	Microsoft Corporation	c:\programdata\microsoft\windows defender\platform\4.18.26080.4-0\mpoav.dll	2026-10-05 21:37.46	677,912	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\amsi.dll	2019-03-19 07:43.57	68,608	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcd.dll	2019-03-19 07:44.35	123,632	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47langs.dll	2019-03-19 07:44.15	369,504	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47mrm.dll	2019-03-19 07:44.15	186,672	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\biwinrt.dll	2019-03-19 07:44.06	308,376	del
Microsoft® Windows® Operating System	5.0.1.1	Microsoft Corporation	c:\windows\system32\cabinet.dll	2019-03-19 07:44.30	146,200	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cfgmgr32.dll	2019-03-19 07:44.35	293,344	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\configmanager2.dll	2019-03-19 07:44.47	664,064	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptbase.dll	2019-03-19 07:44.36	33,848	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptnet.dll	2019-03-19 07:44.33	168,448	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptsp.dll	2019-03-19 07:44.33	80,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\defaultdevicemanager.dll	2019-03-19 07:44.47	21,392	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\devobj.dll	2019-03-19 07:44.35	158,592	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmcfgutils.dll	2019-03-19 07:44.47	108,032	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmcmnutils.dll	2019-03-19 07:44.47	161,672	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmenrollengine.dll	2019-03-19 07:44.47	611,328	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmiso8601utils.dll	2019-03-19 07:44.47	14,848	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmoleaututils.dll	2019-03-19 07:44.47	30,720	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmxmlhelputils.dll	2019-03-19 07:44.06	109,568	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dpapi.dll	2019-03-19 07:44.35	15,872	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dsparse.dll	2019-03-19 07:44.35	30,208	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dusmapi.dll	2019-03-19 07:45.32	48,640	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\enterprisecsps.dll	2019-03-19 07:44.47	1,815,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\enterpriseresourcemanager.dll	2019-03-19 07:44.47	84,480	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\iri.dll	2019-03-19 07:44.47	50,616	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp110_win.dll	2019-03-19 07:43.45	560,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mswb7.dll	2019-03-19 07:43.57	257,184	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncryptsslp.dll	2019-03-19 07:44.35	134,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\netprofm.dll	2019-03-19 07:45.00	226,816	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\npmproxy.dll	2019-03-19 07:45.00	45,056	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\nsi.dll	2019-03-19 07:44.36	25,000	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ntasn1.dll	2019-03-19 07:44.35	241,128	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\oleaut32.dll	2019-06-12 04:33.42	797,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\omadmapi.dll	2019-03-19 07:44.47	164,776	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\onecorecommonproxystub.dll	2019-03-19 07:43.45	479,744	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\policymanager.dll	2019-03-19 07:44.47	514,424	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\productenumerator.dll	2019-03-19 07:44.06	36,352	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\profapi.dll	2019-03-19 07:44.36	110,280	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rasadhlp.dll	2019-03-19 07:45.02	16,896	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\resourcepolicyclient.dll	2019-03-19 07:44.04	70,256	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rsaenh.dll	2019-03-19 07:44.35	202,440	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sspicli.dll	2019-03-19 07:44.36	179,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\storewuauth.dll	2019-03-19 07:44.15	277,504	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\version.dll	2019-03-19 07:45.05	30,680	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\fastprox.dll	2019-03-19 07:43.54	1,031,680	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemprox.dll	2019-03-19 07:43.54	44,544	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemsvc.dll	2019-03-19 07:43.54	63,488	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbemcomn.dll	2019-03-19 07:43.54	487,424	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.devices.enumeration.dll	2019-03-19 07:44.04	523,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.devices.sensors.dll	2019-03-19 07:44.53	1,284,232	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\windows.globalization.dll	2019-06-12 04:33.37	1,784,832	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.graphics.dll	2019-03-19 07:44.06	525,824	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.networking.connectivity.dll	2019-03-19 07:44.00	767,488	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.security.authentication.onlineid.dll	2019-03-19 07:44.04	914,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winnsi.dll	2019-03-19 07:44.36	34,808	del
Microsoft® Windows® Operating System	10.0.18362.53	Microsoft Corporation	c:\windows\system32\winsta.dll	2019-06-12 04:33.42	358,944	del
Microsoft® Windows® Operating System	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wintrust.dll	2019-06-12 04:33.39	363,624	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wtsapi32.dll	2019-03-19 07:44.33	64,792	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wups.dll	2019-03-19 07:44.06	70,144	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuuhext.dll	2019-03-19 07:44.38	497,664	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuuhosdeployment.dll	2019-03-19 07:44.06	207,872	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\xmllite.dll	2019-03-19 07:44.38	211,216	del
umpdc.dll			c:\windows\system32\umpdc.dll	2019-03-19 07:43.49	54,960	del
Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\structuredquery.dll	2019-03-19 07:44.15	676,840	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\advapi32.dll	2019-03-19 07:43.54	655,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcrypt.dll	2019-03-19 07:44.33	144,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certca.dll	2019-03-19 07:44.04	807,424	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certenroll.dll	2019-03-19 07:44.06	3,184,128	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ddores.dll	2019-03-19 07:44.47	47,512	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\devdispitemprovider.dll	2019-03-19 07:44.04	119,328	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dhcpcsvc.dll	2019-03-19 07:44.33	92,672	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dhcpcsvc6.dll	2019-03-19 07:44.33	68,096	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmenterprisediagnostics.dll	2019-03-19 07:44.47	314,880	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dnsapi.dll	2019-03-19 07:44.33	818,888	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\esent.dll	2019-03-19 07:44.15	3,261,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\flightsettings.dll	2019-03-19 07:43.50	892,928	del
Операционная система Microsoft® Windows®	10.0.18362.113	Microsoft Corporation	c:\windows\system32\fwpuclnt.dll	2019-06-12 04:33.39	467,456	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gpapi.dll	2019-03-19 07:44.48	129,808	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\iphlpapi.dll	2019-03-19 07:44.33	229,528	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mskeyprotect.dll	2019-03-19 07:44.06	62,976	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\mswsock.dll	2019-03-19 07:44.33	407,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncrypt.dll	2019-03-19 07:44.35	144,840	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.113	Microsoft Corporation	c:\windows\system32\ole32.dll	2019-06-12 04:33.40	1,395,600	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\powrprof.dll	2019-03-19 07:44.35	291,336	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\schannel.dll	2019-06-12 04:33.42	537,088	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shcore.dll	2019-03-19 07:44.21	684,352	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\shlwapi.dll	2019-03-19 07:45.05	329,200	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\updatepolicy.dll	2019-03-19 07:44.06	200,192	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\userenv.dll	2019-06-12 04:33.42	139,472	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\vaultcli.dll	2019-03-19 07:44.06	289,280	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\webio.dll	2019-03-19 07:44.35	598,016	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\webservices.dll	2019-03-19 07:44.15	1,379,248	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wevtapi.dll	2019-03-19 07:44.18	379,128	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.security.authentication.web.core.dll	2019-03-19 07:44.03	1,166,848	del
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\windows.storage.dll	2019-06-12 04:33.39	7,887,656	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.web.dll	2019-03-19 07:44.01	758,784	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winhttp.dll	2019-03-19 07:44.35	980,248	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wintypes.dll	2019-03-19 07:44.33	1,393,960	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wldap32.dll	2019-03-19 07:44.35	402,432	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\wldp.dll	2019-06-12 04:33.42	161,848	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wosc.dll	2019-03-19 07:43.45	242,688	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ws2_32.dll	2019-03-19 07:44.36	443,424	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuapi.dll	2019-03-19 07:44.06	841,216	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuaueng.dll	2019-03-19 07:44.06	3,104,768	del
Служба Windows® Search	7.0.18362.1	Microsoft Corporation	c:\windows\system32\propsys.dll	2019-03-19 07:44.15	977,680	del
Running Processes\svchost.exe -k netsvcs -p -s wuauserv\Opened Handles\	del
		Directory	\BaseNamedObjects			del
		File	\Device\Afd			del
		File	\Device\CNG			del
		File	\Device\DeviceApi			del
		File	\Device\Harddisk0\DR0			del
		File	\Device\KsecDD			del
		File	\Device\Nsi			del
		Directory	\KnownDlls			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui	2023-06-12 02:28.24	12,680	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.dll.mui	2023-06-12 02:28.24	181,664	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui	2023-06-12 02:28.24	78,240	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		File	C:\Windows\SoftwareDistribution\DataStore\DataStore.edb	2026-10-07 02:06.46	36,700,160	del
		File	C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm	2026-10-07 02:06.46	16,384	del
		File	C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log	2026-10-07 02:06.46	1,310,720	del
		File	C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb	2026-10-07 02:12.57	262,144	del
		File	C:\Windows\SoftwareDistribution\ReportingEvents.log	2026-10-06 22:17.50	399,248	del
		Directory	C:\Windows\System32			del
		File	C:\Windows\System32\ru-RU\ESENT.dll.mui	2019-03-19 14:34.15	150,528	del
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			del
		Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			del
		Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache.v2\Legacy			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
		Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			del
		Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			del
		Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces			del
		Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces			del
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5			del
		Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9			del
		Key	HKU\.DEFAULT			del
		Key	HKU\.DEFAULT\Control Panel\International			del
		Key	HKU\.DEFAULT\Software\Classes			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust			del
		Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople			del
		Key	HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			del
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
Running Processes\svchost.exe -k NetworkService -p -s CryptSvc\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cryptnet.dll	2019-03-19 07:44.33	168,448	add
Running Processes\svchost.exe -k NetworkService -p -s CryptSvc\Opened Handles\	mod
		Directory	C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData			add
Running Processes\svchost.exe -k UnistackSvcGroup -s CDPUserSvc\Opened Handles\	mod
		File	C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal	2026-10-07 02:05.11	3,135,352	old
		File	C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal	2026-10-07 02:12.23	3,510,272	new
Running Processes\svchost.exe -k UnistackSvcGroup -s WpnUserService\Opened Handles\	mod
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal	2026-10-07 01:56.26	1,058,872	old
		File	C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal	2026-10-07 02:08.34	1,347,272	new
Running Processes\SysTracer.exe\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcp47langs.dll	2019-03-19 07:44.15	369,504	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\linkinfo.dll	2019-03-19 07:44.30	30,720	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\nsi.dll	2019-03-19 07:44.36	25,000	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\appresolver.dll	2019-03-19 07:44.21	558,344	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\slc.dll	2019-03-19 07:44.32	140,800	add
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sppc.dll	2019-03-19 07:44.32	136,192	add
Операционная система Microsoft® Windows®	10.0.18362.175	Microsoft Corporation	c:\windows\system32\userenv.dll	2019-06-12 04:33.42	139,472	add
Running Processes\SysTracer.exe\Opened Handles\	mod
		File	\Device\Nsi			add
		File	C:\			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\advapi32.dll.mui	2023-06-12 02:28.22	14,216	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\apphelp.dll.mui	2023-06-12 02:28.22	13,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bcrypt.dll.mui	2023-06-12 02:28.22	13,720	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\comdlg32.dll.mui	2023-06-12 02:28.22	70,552	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\d2d1.dll.mui	2023-06-12 02:28.22	301,456	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\DWrite.dll.mui	2023-06-12 02:28.22	12,680	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iertutil.dll.mui	2023-06-12 02:28.23	13,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iphlpapi.dll.mui	2023-06-12 02:28.23	14,240	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\jscript9.dll.mui	2023-06-12 02:28.23	45,984	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mlang.dll.mui	2023-06-12 02:28.23	28,064	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msctf.dll.mui	2023-06-12 02:28.23	14,736	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msimtf.dll.mui	2023-06-12 02:28.23	12,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ntmarta.dll.mui	2023-06-12 02:28.23	17,296	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oledlg.dll.mui	2023-06-12 02:28.23	40,328	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\powrprof.dll.mui	2023-06-12 02:28.24	80,784	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rpcrt4.dll.mui	2023-06-12 02:28.24	32,664	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\SHCore.dll.mui	2023-06-12 02:28.24	12,696	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\shlwapi.dll.mui	2023-06-12 02:28.24	14,752	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinapi.appcore.dll.mui	2023-06-12 02:28.24	17,800	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIAutomationCore.dll.mui	2023-06-12 02:28.24	30,096	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\uxtheme.dll.mui	2023-06-12 02:28.24	18,824	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winhttp.dll.mui	2023-06-12 02:28.24	31,120	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wininet.dll.mui	2023-06-12 02:28.24	44,944	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wintypes.dll.mui	2023-06-12 02:28.24	12,704	add
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wldp.dll.mui	2023-06-12 02:28.24	17,312	add
		File	C:\Users\user\Desktop\tools\SysTracer x64\data\snap-0.tmp	2026-10-07 02:13.47	0	del
		File	C:\Users\user\Desktop\tools\SysTracer x64\data\snap-1.tmp	2026-10-07 02:30.25	0	add
		Directory	C:\Windows			del
		File	C:\Windows\System32\en-US\sechost.dll.mui	2019-03-19 14:34.30	2,560	add
		File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	add
		File	C:\Windows\System32\ru-RU\kernel32.dll.mui	2019-03-19 14:34.33	1,042,944	add
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	add
		File	C:\Windows\System32\ru-RU\ntdll.dll.mui	2019-03-19 14:34.30	484,864	add
		File	C:\Windows\System32\ru-RU\ole32.dll.mui	2019-03-19 14:34.30	31,232	add
		File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	add
		File	C:\Windows\System32\ru-RU\srpapi.dll.mui	2019-03-19 14:34.30	8,704	add
		File	C:\Windows\System32\ru-RU\winspool.drv.mui	2019-03-19 14:34.27	84,480	add
		File	C:\Windows\System32\ru-RU\ws2_32.dll.mui	2019-03-19 14:34.30	24,576	add
		Directory	C:\Windows\WinSxS			del
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34			add
		File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34\comctl32.dll.mui	2019-06-12 04:33.42	6,144	add
		Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d			add
		File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui	2019-06-12 04:33.42	12,288	add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
		Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
		Key	HKLM\SOFTWARE\WOW6432Node\Classes			add
		Key	HKLM\SOFTWARE\WOW6432Node\Clients			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cellular			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\COM3			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Current			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Readers			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\SystemShared			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\DeviceReg			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\DFS			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Driver Signing			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\EnterpriseCertificates			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\EventSystem			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\FingerKB			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\FuzzyDS			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Input			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\LanguageOverlay			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Messaging			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MSMQ			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFFuzzyFactors			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFInputType			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFKeyboardMappings			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Non-Driver Signing			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Notepad\DefaultFonts			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Ole			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Phone			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Pim			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Poom			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Ras			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Rpc			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Semgr			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Shell			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Software\Microsoft\Shared Tools\Msinfo			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\TermServLicensing			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Transaction Server			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Unified Store			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\UserData			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Console			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Containers			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontDPI			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontLink			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontMapper			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Fonts			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontSubstitutes			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\LanguagePack			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\NetworkCards			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Ports			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Print			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows Search			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Theme			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\ThemeVolatile			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Group Policy			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Parental Controls			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PreviewHandlers			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Telephony\Locations			add
		Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\XAML			add
		Key	HKLM\SOFTWARE\WOW6432Node\Policies			add
		Key	HKLM\SOFTWARE\WOW6432Node\RegisteredApplications			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Print\Printers			add
		Key	HKLM\SYSTEM\ControlSet001\Control\Video\{7C8C3757-C0DF-11F1-B68A-806E6F6E6963}\0000			add
		Key	HKLM\SYSTEM\ControlSet001\Hardware Profiles\Current			add
		Key	HKLM\SYSTEM\CurrentControlSet			add
		Key	HKLM\SYSTEM\HardwareConfig\Current			add
		Key	HKU			del
		Key	HKU\S-1-5-18			add
		Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
Running Processes\wmiprvse.exe\	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\cfgmgr32.dll	2019-03-19 07:44.35	293,344	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\devobj.dll	2019-03-19 07:44.35	158,592	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dxcore.dll	2019-03-19 07:44.06	112,296	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\framedynos.dll	2019-03-19 07:43.54	305,664	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\imagehlp.dll	2019-03-19 07:44.35	108,936	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msasn1.dll	2019-03-19 07:44.35	63,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncobjapi.dll	2019-03-19 07:43.54	73,728	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ntasn1.dll	2019-03-19 07:44.35	241,128	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\oleaut32.dll	2019-06-12 04:33.42	797,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sspicli.dll	2019-03-19 07:44.36	179,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\tbs.dll	2019-03-19 07:43.54	48,048	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\fastprox.dll	2019-03-19 07:43.54	1,031,680	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemprox.dll	2019-03-19 07:43.54	44,544	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemsvc.dll	2019-03-19 07:43.54	63,488	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\win32_tpm.dll	2019-03-19 07:43.54	79,360	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbemcomn.dll	2019-03-19 07:43.54	487,424	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.53	Microsoft Corporation	c:\windows\system32\winsta.dll	2019-06-12 04:33.42	358,944	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wtsapi32.dll	2019-03-19 07:44.33	64,792	del
umpdc.dll			c:\windows\system32\umpdc.dll	2019-03-19 07:43.49	54,960	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\advapi32.dll	2019-03-19 07:43.54	655,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcrypt.dll	2019-03-19 07:44.33	144,144	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\crypt32.dll	2019-03-19 07:44.33	1,326,856	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncrypt.dll	2019-03-19 07:44.35	144,840	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\powrprof.dll	2019-03-19 07:44.35	291,336	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\tpmcoreprovisioning.dll	2019-03-19 07:43.54	1,092,096	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\cimwin32.dll	2019-03-19 07:44.00	2,054,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wmiutils.dll	2019-03-19 07:43.54	131,584	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winhttp.dll	2019-03-19 07:44.35	980,248	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ws2_32.dll	2019-03-19 07:44.36	443,424	del
Running Processes\wmiprvse.exe\Opened Handles\	del
		Directory	\BaseNamedObjects			del
		File	\Device\CNG			del
		File	\Device\DeviceApi			del
		File	\Device\KsecDD			del
		Directory	\KnownDlls			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui	2023-06-12 02:28.24	29,576	del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\wbem\ru-RU\cimwin32.dll.mui	2023-06-12 02:28.25	20,888	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
Running Processes\wmiprvse.exe\	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\bcryptprimitives.dll	2019-06-12 04:33.43	529,072	del
Microsoft® Windows® Operating System	2001.12.10941.16384	Microsoft Corporation	c:\windows\system32\clbcatq.dll	2019-03-19 07:44.30	643,752	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\gdi32.dll	2019-03-19 07:44.06	147,912	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\gdi32full.dll	2019-06-12 04:33.43	1,647,584	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\kernel.appcore.dll	2019-03-19 07:44.15	59,088	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcp_win.dll	2019-03-19 07:44.33	639,632	del
Microsoft® Windows® Operating System	7.0.18362.1	Microsoft Corporation	c:\windows\system32\msvcrt.dll	2019-03-19 07:44.35	638,072	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ncobjapi.dll	2019-03-19 07:43.54	73,728	del
Microsoft® Windows® Operating System	10.0.18362.86	Microsoft Corporation	c:\windows\system32\oleaut32.dll	2019-06-12 04:33.42	797,112	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\sechost.dll	2019-03-19 07:44.36	606,104	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ucrtbase.dll	2019-03-19 07:44.33	1,020,776	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\esscli.dll	2019-03-19 07:43.54	468,992	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\fastprox.dll	2019-03-19 07:43.54	1,031,680	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemprox.dll	2019-03-19 07:43.54	44,544	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wbemsvc.dll	2019-03-19 07:43.54	63,488	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wmiprov.dll	2019-03-19 07:44.00	218,624	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbemcomn.dll	2019-03-19 07:43.54	487,424	del
Microsoft® Windows® Operating System	10.0.18362.175	Microsoft Corporation	c:\windows\system32\win32u.dll	2019-06-12 04:33.39	127,064	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wmiclnt.dll	2019-03-19 07:43.45	46,592	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\advapi32.dll	2019-03-19 07:43.54	655,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\bcrypt.dll	2019-03-19 07:44.33	144,144	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\combase.dll	2019-06-12 04:33.42	3,373,256	del
Операционная система Microsoft® Windows®	10.0.18362.86	Microsoft Corporation	c:\windows\system32\kernel32.dll	2019-06-12 04:33.37	722,072	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\kernelbase.dll	2019-06-12 04:33.43	2,763,312	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\ntdll.dll	2019-06-12 04:33.42	1,999,440	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ntmarta.dll	2019-03-19 07:44.35	181,856	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\rpcrt4.dll	2019-03-19 07:44.36	1,171,192	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\user32.dll	2019-03-19 07:44.15	1,654,544	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wmiutils.dll	2019-03-19 07:43.54	131,584	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ws2_32.dll	2019-03-19 07:44.36	443,424	del
Running Processes\wmiprvse.exe\Opened Handles\	del
		Directory	\BaseNamedObjects			del
		File	\Device\CNG			del
		File	\Device\KsecDD			del
		File	\Device\WMIDataDevice			del
		Directory	\KnownDlls			del
		File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui	2023-06-12 02:28.24	29,576	del
		File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
		Directory	C:\Windows\System32			del
		File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	del
		File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
		Key	HKLM			del
		Key	HKLM\SOFTWARE\Classes			del
		Key	HKLM\SOFTWARE\Classes\PackagedCom			del
		Key	HKLM\SOFTWARE\Microsoft\Ole			del
		Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
		Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
		Key	HKU\.DEFAULT\Software\Classes			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings			del
		Key	HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft			del
Loaded Dlls\	mod
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\capabilityaccesshandlers.dll	2019-03-19 07:44.06	65,024	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\configmanager2.dll	2019-03-19 07:44.47	664,064	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\defaultdevicemanager.dll	2019-03-19 07:44.47	21,392	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmiso8601utils.dll	2019-03-19 07:44.47	14,848	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmoleaututils.dll	2019-03-19 07:44.47	30,720	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\enterprisecsps.dll	2019-03-19 07:44.47	1,815,040	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\enterpriseresourcemanager.dll	2019-03-19 07:44.47	84,480	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ktmw32.dll	2019-03-19 07:44.53	24,576	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnr.dll	2019-03-19 07:44.06	617,472	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnrgidshandler.dll	2019-03-19 07:44.38	488,448	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\productenumerator.dll	2019-03-19 07:44.06	36,352	del
Microsoft® Windows® Operating System	4.18.1901.16384	Microsoft Corporation	c:\windows\system32\securityhealthproxystub.dll	2019-03-19 07:44.39	106,296	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\smartscreenps.dll	2019-03-19 07:44.03	256,000	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\storewuauth.dll	2019-03-19 07:44.15	277,504	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\win32_tpm.dll	2019-03-19 07:43.54	79,360	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\wmiprov.dll	2019-03-19 07:44.00	218,624	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\windows.devices.sensors.dll	2019-03-19 07:44.53	1,284,232	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\winrttracing.dll	2019-03-19 07:44.01	189,952	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64.dll	2019-03-19 07:44.38	335,752	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64cpu.dll	2019-03-19 07:44.38	20,728	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wow64win.dll	2019-03-19 07:44.38	510,488	add
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuuhext.dll	2019-03-19 07:44.38	497,664	del
Microsoft® Windows® Operating System	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuuhosdeployment.dll	2019-03-19 07:44.06	207,872	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\authui.dll	2019-03-19 07:44.00	261,120	del
Операционная система Microsoft® Windows®	10.0.18362.145	Microsoft Corporation	c:\windows\system32\capabilityaccessmanager.dll	2019-06-12 04:33.38	344,576	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certca.dll	2019-03-19 07:44.04	807,424	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\certenroll.dll	2019-03-19 07:44.06	3,184,128	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ddores.dll	2019-03-19 07:44.47	47,512	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\dmenterprisediagnostics.dll	2019-03-19 07:44.47	314,880	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ehstorapi.dll	2019-03-19 07:45.38	132,096	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\ngcctnrsvc.dll	2019-03-19 07:44.06	810,496	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\tpmcoreprovisioning.dll	2019-03-19 07:43.54	1,092,096	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wbem\cimwin32.dll	2019-03-19 07:44.00	2,054,144	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wosc.dll	2019-03-19 07:43.45	242,688	del
Операционная система Microsoft® Windows®	10.0.18362.1	Microsoft Corporation	c:\windows\system32\wuaueng.dll	2019-03-19 07:44.06	3,104,768	del
Opened Handles\	mod
Microsoft® Windows® Operating System	C:\Windows\system32\lsass.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msprivs.dll.mui	2023-06-12 02:28.23	15,776	add
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Directory	\BaseNamedObjects			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	\Device\CNG			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	\Device\DeviceApi			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	\Device\KsecDD			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	\Device\WMIDataDevice			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Directory	\KnownDlls			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui	2023-06-12 02:28.24	29,576	del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\wbem\ru-RU\cimwin32.dll.mui	2023-06-12 02:28.25	20,888	del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Directory	C:\Windows\System32			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SOFTWARE\Classes			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SOFTWARE\Classes\PackagedCom			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SOFTWARE\Microsoft\Ole			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKU\.DEFAULT\Software\Classes			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKU\.DEFAULT\Software\Classes\Local Settings			del
Microsoft® Windows® Operating System	C:\Windows\system32\wbem\wmiprvse.exe	Key	HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft			del
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	\Device\CNG			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	\Device\DeviceApi			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	\Device\KsecDD			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	\Device\Nsi			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Directory	\KnownDlls			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Directory	\KnownDlls32			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Directory	\Sessions\1\BaseNamedObjects			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rundll32.exe.mui	2023-06-12 02:28.24	13,208	add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Directory	C:\Users\user\AppData\Roaming\Microsoft			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Directory	C:\Windows			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\Ole			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Policies			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			add
Microsoft® Windows® Operating System	C:\Windows\SysWOW64\rundll32.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			add
Process Hacker	C:\Program Files\Process Hacker 2\ProcessHacker.exe	File	C:\Windows\System32\ru-RU\ntdll.dll.mui	2019-03-19 14:34.30	484,864	add
Process Hacker	C:\Program Files\Process Hacker 2\ProcessHacker.exe	Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d			add
Process Hacker	C:\Program Files\Process Hacker 2\ProcessHacker.exe	File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui	2019-06-12 04:33.42	12,288	add
Process Hacker	C:\Program Files\Process Hacker 2\ProcessHacker.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	\FileSystem\Filters\FltMgrMsg			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc.dll.mui	2023-06-12 02:28.22	13,216	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc6.dll.mui	2023-06-12 02:28.22	39,832	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui	2023-06-12 02:28.22	37,792	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\napinsp.dll.mui	2023-06-12 02:28.23	13,216	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui	2023-06-12 02:28.23	30,616	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnrpnsp.dll.mui	2023-06-12 02:28.23	13,208	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wship6.dll.mui	2023-06-12 02:28.25	13,216	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshqos.dll.mui	2023-06-12 02:28.25	13,216	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshtcpip.dll.mui	2023-06-12 02:28.25	13,216	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db	2023-06-12 15:55.27	1,048,576	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Directory	C:\Users\user\Desktop\tools\ProcessMonitor			old
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Directory	C:\Users\user\Desktop\tools\ProcessMonitor			new
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Windows\SystemResources\comdlg32.dll.mun	2019-03-19 07:45.05	352,768	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Windows\SystemResources\ExplorerFrame.dll.mun	2019-03-19 07:45.05	2,640,896	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	File	C:\Windows\SystemResources\shell32.dll.mun	2019-06-12 04:33.41	14,768,128	add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{088e3905-0323-4b02-9826-5d99428e115f}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{24ad3ad4-a569-4530-98e1-ab02f9417aa8}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{d3162b92-9365-467a-956b-92703aca08af}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\Shell			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Policies			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKLM\SOFTWARE\WOW6432Node			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell			add
Sysinternals Procmon	C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	\Device\Nsi			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\			del
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\advapi32.dll.mui	2023-06-12 02:28.22	14,216	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\apphelp.dll.mui	2023-06-12 02:28.22	13,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bcrypt.dll.mui	2023-06-12 02:28.22	13,720	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\comdlg32.dll.mui	2023-06-12 02:28.22	70,552	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\d2d1.dll.mui	2023-06-12 02:28.22	301,456	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\DWrite.dll.mui	2023-06-12 02:28.22	12,680	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iertutil.dll.mui	2023-06-12 02:28.23	13,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iphlpapi.dll.mui	2023-06-12 02:28.23	14,240	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\jscript9.dll.mui	2023-06-12 02:28.23	45,984	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mlang.dll.mui	2023-06-12 02:28.23	28,064	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msctf.dll.mui	2023-06-12 02:28.23	14,736	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msimtf.dll.mui	2023-06-12 02:28.23	12,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ntmarta.dll.mui	2023-06-12 02:28.23	17,296	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oledlg.dll.mui	2023-06-12 02:28.23	40,328	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\powrprof.dll.mui	2023-06-12 02:28.24	80,784	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui	2023-06-12 02:28.24	94,112	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rpcrt4.dll.mui	2023-06-12 02:28.24	32,664	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\SHCore.dll.mui	2023-06-12 02:28.24	12,696	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\shlwapi.dll.mui	2023-06-12 02:28.24	14,752	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinapi.appcore.dll.mui	2023-06-12 02:28.24	17,800	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIAutomationCore.dll.mui	2023-06-12 02:28.24	30,096	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\uxtheme.dll.mui	2023-06-12 02:28.24	18,824	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui	2023-06-12 02:28.24	40,864	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winhttp.dll.mui	2023-06-12 02:28.24	31,120	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wininet.dll.mui	2023-06-12 02:28.24	44,944	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wintypes.dll.mui	2023-06-12 02:28.24	12,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wldp.dll.mui	2023-06-12 02:28.24	17,312	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Users\user\Desktop\tools\SysTracer x64\data\snap-0.tmp	2026-10-07 02:14.00	6,306,356	del
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Users\user\Desktop\tools\SysTracer x64\data\snap-1.tmp	2026-10-07 02:30.43	22,162,357	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Directory	C:\Windows			del
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\en-US\sechost.dll.mui	2019-03-19 14:34.30	2,560	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\combase.dll.mui	2019-03-19 14:34.30	40,960	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\kernel32.dll.mui	2019-03-19 14:34.33	1,042,944	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\ntdll.dll.mui	2019-03-19 14:34.30	484,864	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\ole32.dll.mui	2019-03-19 14:34.30	31,232	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\shell32.dll.mui	2019-03-19 14:34.32	478,720	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\srpapi.dll.mui	2019-03-19 14:34.30	8,704	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\winspool.drv.mui	2019-03-19 14:34.27	84,480	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\System32\ru-RU\ws2_32.dll.mui	2019-03-19 14:34.30	24,576	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Directory	C:\Windows\WinSxS			del
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34\comctl32.dll.mui	2019-06-12 04:33.42	6,144	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Directory	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	File	C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui	2019-06-12 04:33.42	12,288	add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Classes			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Clients			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cellular			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\COM3			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Current			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Readers			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\SystemShared			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\DeviceReg			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\DFS			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Driver Signing			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\EnterpriseCertificates			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\EventSystem			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\FingerKB			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\FuzzyDS			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Input			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\LanguageOverlay			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Messaging			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MSMQ			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFFuzzyFactors			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFInputType			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFKeyboardMappings			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Non-Driver Signing			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Notepad\DefaultFonts			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Ole			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Phone			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Pim			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Poom			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Ras			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Rpc			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Semgr			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Shell			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Software\Microsoft\Shared Tools\Msinfo			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\TermServLicensing			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Transaction Server			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Unified Store			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\UserData			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Console			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Containers			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontDPI			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontLink			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontMapper			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Fonts			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontSubstitutes			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\LanguagePack			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\NetworkCards			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Ports			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Print			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows Search			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Theme			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\ThemeVolatile			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Group Policy			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Parental Controls			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PreviewHandlers			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Telephony\Locations			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Microsoft\XAML			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\Policies			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SOFTWARE\WOW6432Node\RegisteredApplications			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Print\Printers			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Video\{7C8C3757-C0DF-11F1-B68A-806E6F6E6963}\0000			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SYSTEM\ControlSet001\Hardware Profiles\Current			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SYSTEM\CurrentControlSet			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKLM\SYSTEM\HardwareConfig\Current			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKU			del
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKU\S-1-5-18			add
SysTracer v2.10	C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts			add
Операционная система Microsoft® Windows®	C:\Windows\Explorer.EXE	Directory	C:\Users\user\Desktop\lab1\src			old
Операционная система Microsoft® Windows®	C:\Windows\Explorer.EXE	Directory	C:\Users\user\Desktop\lab1\src			new
Операционная система Microsoft® Windows®	C:\Windows\Explorer.EXE	File	C:\Windows\System32\ru-RU\ieframe.dll.mui	2019-03-19 14:34.16	1,805,824	add
Операционная система Microsoft® Windows®	C:\Windows\Explorer.EXE	Key	HKLM\SOFTWARE\Classes			del
Операционная система Microsoft® Windows®	C:\Windows\Explorer.EXE	Key	HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance			add
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	\Device\CNG			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	\Device\KsecDD			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	\Device\Nsi			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Directory	\KnownDlls			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Directory	\Sessions\1\BaseNamedObjects			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui	2023-06-12 02:28.22	55,704	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui	2023-06-12 02:28.23	23,968	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\smartscreen.exe.mui	2023-06-12 02:28.24	25,488	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.Http.dll.mui	2023-06-12 02:28.24	23,968	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Windows\Registration\R000000000006.clb	2023-06-12 00:13.07	27,356	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Directory	C:\Windows\System32			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Windows\System32\ru-RU\KernelBase.dll.mui	2019-03-19 14:34.31	1,342,464	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	File	C:\Windows\System32\WinMetadata\Windows.Foundation.winmd	2019-03-19 07:45.02	69,328	del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Internet Explorer\Security			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Ole			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\CA			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Policies			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SOFTWARE\WOW6432Node			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Control\Session Manager			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Services\crypt32			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings			del
Операционная система Microsoft® Windows®	C:\Windows\System32\smartscreen.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.dll.mui	2023-06-12 02:28.24	181,664	del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd	2026-10-07 02:05.30	7,340,032	old
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd	2026-10-07 02:14.29	7,340,032	new
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm	2026-10-07 02:04.47	32,768	old
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm	2026-10-07 02:15.37	32,768	new
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal	2026-10-07 02:04.48	8,272	old
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal	2026-10-07 02:14.29	0	new
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal	2026-10-07 02:12.23	3,510,272	old
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal	2026-10-07 02:30.10	4,111,792	new
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Directory	C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData			add
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Windows\SoftwareDistribution\DataStore\DataStore.edb	2026-10-07 02:06.46	36,700,160	del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm	2026-10-07 02:06.46	16,384	del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log	2026-10-07 02:06.46	1,310,720	del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb	2026-10-07 02:12.57	262,144	del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	File	C:\Windows\SoftwareDistribution\ReportingEvents.log	2026-10-07 02:13.09	400,372	del
Операционная система Microsoft® Windows®	C:\Windows\System32\svchost.exe	File	C:\Windows\System32\winevt\Logs\microsoft-windows-diagnosis-scripted%4operational.evtx	2026-10-05 22:03.02	69,632	add
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Directory	C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\trust			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache.v2\Legacy			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople			del
Операционная система Microsoft® Windows®	C:\Windows\system32\svchost.exe	Key	HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates			del
Служба Windows® Search	C:\Windows\system32\SearchIndexer.exe	File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr	2026-10-07 02:04.48	36,678	old
Служба Windows® Search	C:\Windows\system32\SearchIndexer.exe	File	C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr	2026-10-07 02:15.33	36,928	new
Opened Ports\	mod
-	-	TCP	10.0.2.15	49698	104.18.12.149	80	TIME_WAIT	del
-	-	TCP	10.0.2.15	49699	104.18.12.149	443	TIME_WAIT	del
-	-	TCP	10.0.2.15	49700	104.18.10.31	443	TIME_WAIT	del
-	-	TCP	10.0.2.15	49701	172.184.231.67	443	TIME_WAIT	del
-	-	TCP	10.0.2.15	49703	74.178.240.51	443	TIME_WAIT	del
-	-	TCP	10.0.2.15	49704	20.52.64.203	443	TIME_WAIT	del
-	-	TCP	10.0.2.15	49705	4.207.44.77	443	TIME_WAIT	del