Загрузка данных
Startup\ mod
.lnk 10.0.18362.1 Microsoft Corporation Auto C:\Windows\SysWOW64\rundll32.exe 2019-03-19 07:45.32 61,952 add
Services\ mod
Клиент групповой политики 10.0.18362.1 Microsoft Corporation Auto C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Run Auto C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 new
Контейнер службы Microsoft Passport 10.0.18362.1 Microsoft Corporation Run Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 new
Служба диспетчера доступа к возможностям 10.0.18362.1 Microsoft Corporation Run Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 new
Служба лицензий клиента (ClipSVC) 10.0.18362.1 Microsoft Corporation Run Manual C:\Windows\System32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Manual C:\Windows\System32\svchost.exe 2019-03-19 07:44.33 53,744 new
Служба развертывания AppX (AppXSVC) 10.0.18362.1 Microsoft Corporation Run Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 new
Центр обновления Windows 10.0.18362.1 Microsoft Corporation Run Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 old
10.0.18362.1 Microsoft Corporation Manual C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 new
Running Processes\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation C:\Windows\system32\wbem\wmiprvse.exe 2019-03-19 07:44.00 483,840 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation C:\Windows\system32\wbem\wmiprvse.exe 2019-03-19 07:44.00 483,840 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation C:\Windows\SysWOW64\rundll32.exe 2019-03-19 07:45.32 61,952 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation C:\Windows\System32\smartscreen.exe 2019-03-19 07:44.03 2,759,680 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation C:\Windows\system32\svchost.exe 2019-03-19 07:44.33 53,744 del
Running Processes\Explorer.EXE\ mod
Internet Explorer 11.0.18362.1 Microsoft Corporation c:\windows\system32\msiso.dll 2019-03-19 07:44.50 308,736 add
Microsoft® Windows® Operating System 10.0.18362.113 Microsoft Corporation c:\windows\system32\cryptdll.dll 2019-06-12 04:33.42 66,360 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\execmodelproxy.dll 2019-03-19 07:44.03 83,456 add
Microsoft® Windows® Operating System 4.18.1901.16384 Microsoft Corporation c:\windows\system32\securityhealthproxystub.dll 2019-03-19 07:44.39 106,296 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\storageusage.dll 2019-06-12 04:33.50 130,560 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.cloudstore.schema.shell.dll 2019-03-19 07:43.57 1,113,088 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\authui.dll 2019-03-19 07:44.00 261,120 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\capauthz.dll 2019-03-19 07:44.01 313,016 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ehstorapi.dll 2019-03-19 07:45.38 132,096 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\execmodelclient.dll 2019-03-19 07:44.03 318,176 add
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\windows.internal.shell.broker.dll 2019-06-12 04:33.44 888,056 add
Служба Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\tquery.dll 2019-03-19 07:44.11 3,263,488 add
Running Processes\Explorer.EXE\Opened Handles\ mod
File \Device\CNG del
File \Device\DeviceApi del
File \Device\KsecDD del
File \Device\Nsi del
File \Device\WMIDataDevice del
File \FileSystem\Filters\FltMgrMsg del
Directory \KnownDlls del
Directory \Sessions\1\BaseNamedObjects del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Program Files\Windows Defender\ru-RU\shellext.dll.mui 2023-06-12 02:28.21 13,720 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\acppage.dll.mui 2023-06-12 02:28.22 27,040 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ActionCenter.dll.mui 2023-06-12 02:28.22 59,296 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ApplicationFrame.dll.mui 2023-06-12 02:28.22 13,720 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bthprops.cpl.mui 2023-06-12 02:28.22 27,544 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dui70.dll.mui 2023-06-12 02:28.22 15,248 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui 2023-06-12 02:28.22 37,792 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\hcproviders.dll.mui 2023-06-12 02:28.23 17,824 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\InputSwitch.dll.mui 2023-06-12 02:28.23 18,848 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mpr.dll.mui 2023-06-12 02:28.23 12,704 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui 2023-06-12 02:28.23 30,616 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnidui.dll.mui 2023-06-12 02:28.23 18,840 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\sndvolsso.dll.mui 2023-06-12 02:28.24 17,312 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\stobject.dll.mui 2023-06-12 02:28.24 18,848 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twext.dll.mui 2023-06-12 02:28.24 16,280 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinui.pcshell.dll.mui 2023-06-12 02:28.24 16,288 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIRibbon.dll.mui 2023-06-12 02:28.24 50,056 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui 2023-06-12 02:28.24 29,576 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui 2023-06-12 02:28.24 78,240 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wscui.cpl.mui 2023-06-12 02:28.25 98,200 del
Directory C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe del
Directory C:\ProgramData\Microsoft\Windows\Start Menu del
Directory C:\ProgramData\Microsoft\Windows\Start Menu\Programs del
Directory C:\ProgramData\Microsoft\Windows\WER\ReportArchive del
Directory C:\Users\Public\Desktop del
Directory C:\Users\user\AppData\Local\Microsoft\GameDVR del
File C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin 2026-10-05 20:31.00 1,848,932 del
Directory C:\Users\user\AppData\Local\Microsoft\Windows\Burn del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 2023-06-12 15:55.27 1,048,576 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db 2026-10-05 20:34.56 2,097,152 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db 2026-10-06 02:42.01 4,194,304 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db 2026-10-05 21:58.11 116,496 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db 2023-06-12 15:55.30 1,048,576 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db 2023-06-12 15:55.30 1,048,576 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db 2023-06-12 15:55.30 1,048,576 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db 2023-06-12 15:55.30 1,048,576 del
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db 2023-09-08 11:07.24 29,232 del
Directory C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC del
Directory C:\Users\user\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache del
Directory C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned del
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries del
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts del
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts del
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu del
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs del
Directory C:\Users\user\Desktop del
Directory C:\Users\user\Desktop\lab1 del
Directory C:\Users\user\Desktop\lab1\src del
Directory C:\Users\user\Documents del
Directory C:\Users\user\Downloads del
Directory C:\Users\user\Pictures del
Directory C:\Windows\bcastdvr del
File C:\Windows\Fonts\segoeui.ttf 2019-03-19 07:44.11 955,804 del
File C:\Windows\Fonts\StaticCache.dat 2019-06-12 04:33.43 19,333,120 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
File C:\Windows\ru-RU\explorer.exe.mui 2019-03-19 14:34.27 14,848 del
Directory C:\Windows\System32 del
File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 del
File C:\Windows\System32\ru-RU\dsreg.dll.mui 2019-06-12 04:33.59 47,104 del
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
File C:\Windows\System32\ru-RU\ole32.dll.mui 2019-03-19 14:34.30 31,232 del
File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 del
File C:\Windows\System32\WinMetadata\Windows.UI.winmd 2019-03-19 07:45.02 654,288 del
File C:\Windows\SystemResources\ExplorerFrame.dll.mun 2019-03-19 07:45.05 2,640,896 del
File C:\Windows\SystemResources\imageres.dll.mun 2019-03-19 07:43.55 22,571,008 del
File C:\Windows\SystemResources\shell32.dll.mun 2019-06-12 04:33.41 14,768,128 del
File C:\Windows\SystemResources\SndVolSSO.dll.mun 2019-03-19 07:44.28 587,776 del
File C:\Windows\SystemResources\stobject.dll.mun 2019-03-19 07:43.55 132,608 del
Directory C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9 del
Directory C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97 del
Key HKLM del
Key HKLM\SOFTWARE del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Classes\CLSID\{1f3427c8-5c10-4210-aa03-2ee45287d668}\Instance del
Key HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance del
Key HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance del
Key HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance del
Key HKLM\SOFTWARE\Classes\CLSID\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\Instance del
Key HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance del
Key HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{0D7AC4D6-88C0-42F4-9352-237C536DA832} del
Key HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{CDE990B0-E58E-4B56-9042-3691614CF4D0} del
Key HKLM\SOFTWARE\Classes\PackagedCom del
Key HKLM\SOFTWARE\Classes\PackagedCom\ClassIndex del
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople del
Key HKLM\SOFTWARE\Microsoft\IdentityStore\Providers del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security del
Key HKLM\SOFTWARE\Microsoft\KGL\OneSettings del
Key HKLM\SOFTWARE\Microsoft\MSF\Registration\Listen del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\PlayToReceiver del
Key HKLM\SOFTWARE\Microsoft\Security Center del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople del
Key HKLM\SOFTWARE\Microsoft\TabletTip\1.7 del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.help del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.newfolder del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.properties del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.redo del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.rename del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.RibbonDelete del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.undo del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PerceptionSimulationExtensions del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore del
Key HKLM\SOFTWARE\Microsoft\Windows\Shell del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server del
Key HKLM\SOFTWARE\Policies del
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates del
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\WOW6432Node del
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder del
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder del
Key HKLM\SYSTEM\ControlSet001\Control\NetworkUxManager del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKLM\SYSTEM\ControlSet001\Services\crypt32 del
Key HKU del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Colors del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Desktop del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Keyboard del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\GameBar del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\MSF\Registration\Listen del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\TabletTip\1.7 del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollection\Current del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollectionlocal\Current del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstarttilepropertiesmap\Current del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstartvolatiletilepropertiesmap\Current del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.roamedtilepropertiesmap\Current del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\BannerStore del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ModeTriggerCachedKey del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{BCB48336-4DDD-48FF-BB0B-D3190DACB3E2}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}\Count del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\VirtualDesktops del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\GameDVR del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Holographic del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell\Bags\1\Desktop del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\WorkFolders del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache del
File \Device\CNG add
File \Device\DeviceApi add
File \Device\KsecDD add
File \Device\Nsi add
File \Device\WMIDataDevice add
File \FileSystem\Filters\FltMgrMsg add
Directory \KnownDlls add
Directory \Sessions\1\BaseNamedObjects add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Program Files\Windows Defender\ru-RU\shellext.dll.mui 2023-06-12 02:28.21 13,720 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\acppage.dll.mui 2023-06-12 02:28.22 27,040 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ActionCenter.dll.mui 2023-06-12 02:28.22 59,296 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ApplicationFrame.dll.mui 2023-06-12 02:28.22 13,720 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bthprops.cpl.mui 2023-06-12 02:28.22 27,544 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dui70.dll.mui 2023-06-12 02:28.22 15,248 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui 2023-06-12 02:28.22 37,792 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\hcproviders.dll.mui 2023-06-12 02:28.23 17,824 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\InputSwitch.dll.mui 2023-06-12 02:28.23 18,848 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mpr.dll.mui 2023-06-12 02:28.23 12,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui 2023-06-12 02:28.23 30,616 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnidui.dll.mui 2023-06-12 02:28.23 18,840 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\sndvolsso.dll.mui 2023-06-12 02:28.24 17,312 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\stobject.dll.mui 2023-06-12 02:28.24 18,848 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twext.dll.mui 2023-06-12 02:28.24 16,280 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinui.pcshell.dll.mui 2023-06-12 02:28.24 16,288 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIRibbon.dll.mui 2023-06-12 02:28.24 50,056 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui 2023-06-12 02:28.24 29,576 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui 2023-06-12 02:28.24 78,240 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wscui.cpl.mui 2023-06-12 02:28.25 98,200 add
Directory C:\Program Files\WindowsApps\Microsoft.XboxGameOverlay_1.54.4001.0_x64__8wekyb3d8bbwe add
Directory C:\ProgramData\Microsoft\Windows\Start Menu add
Directory C:\ProgramData\Microsoft\Windows\Start Menu\Programs add
Directory C:\ProgramData\Microsoft\Windows\WER\ReportArchive add
Directory C:\Users\Public\Desktop add
Directory C:\Users\user\AppData\Local\Microsoft\GameDVR add
File C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin 2026-10-05 20:31.00 1,848,932 add
Directory C:\Users\user\AppData\Local\Microsoft\Windows\Burn add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 2023-06-12 15:55.27 1,048,576 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db 2026-10-05 20:34.56 2,097,152 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db 2026-10-06 02:42.01 4,194,304 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db 2026-10-05 21:58.11 116,496 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db 2023-06-12 15:55.30 1,048,576 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db 2023-06-12 15:55.30 1,048,576 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db 2023-06-12 15:55.30 1,048,576 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db 2023-06-12 15:55.30 1,048,576 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db 2023-09-08 11:07.24 29,232 add
Directory C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC add
Directory C:\Users\user\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache add
Directory C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned add
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries add
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts add
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts add
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu add
Directory C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs add
Directory C:\Users\user\Desktop add
Directory C:\Users\user\Desktop\lab1 add
Directory C:\Users\user\Desktop\lab1\src add
Directory C:\Users\user\Documents add
Directory C:\Users\user\Downloads add
Directory C:\Users\user\Pictures add
Directory C:\Windows\bcastdvr add
File C:\Windows\Fonts\segoeui.ttf 2019-03-19 07:44.11 955,804 add
File C:\Windows\Fonts\StaticCache.dat 2019-06-12 04:33.43 19,333,120 add
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 add
File C:\Windows\ru-RU\explorer.exe.mui 2019-03-19 14:34.27 14,848 add
Directory C:\Windows\System32 add
File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 add
File C:\Windows\System32\ru-RU\dsreg.dll.mui 2019-06-12 04:33.59 47,104 add
File C:\Windows\System32\ru-RU\ieframe.dll.mui 2019-03-19 14:34.16 1,805,824 add
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 add
File C:\Windows\System32\ru-RU\ole32.dll.mui 2019-03-19 14:34.30 31,232 add
File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 add
File C:\Windows\System32\WinMetadata\Windows.UI.winmd 2019-03-19 07:45.02 654,288 add
File C:\Windows\SystemResources\ExplorerFrame.dll.mun 2019-03-19 07:45.05 2,640,896 add
File C:\Windows\SystemResources\imageres.dll.mun 2019-03-19 07:43.55 22,571,008 add
File C:\Windows\SystemResources\shell32.dll.mun 2019-06-12 04:33.41 14,768,128 add
File C:\Windows\SystemResources\SndVolSSO.dll.mun 2019-03-19 07:44.28 587,776 add
File C:\Windows\SystemResources\stobject.dll.mun 2019-03-19 07:43.55 132,608 add
Directory C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9 add
Directory C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97 add
Key HKLM add
Key HKLM\SOFTWARE add
Key HKLM\SOFTWARE\Classes\CLSID\{1f3427c8-5c10-4210-aa03-2ee45287d668}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance add
Key HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{0D7AC4D6-88C0-42F4-9352-237C536DA832} add
Key HKLM\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Deployment\Package\*\S-1-5-21-2292890337-69778762-837601055-1001\{CDE990B0-E58E-4B56-9042-3691614CF4D0} add
Key HKLM\SOFTWARE\Classes\PackagedCom add
Key HKLM\SOFTWARE\Classes\PackagedCom\ClassIndex add
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople add
Key HKLM\SOFTWARE\Microsoft\IdentityStore\Providers add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security add
Key HKLM\SOFTWARE\Microsoft\KGL\OneSettings add
Key HKLM\SOFTWARE\Microsoft\MSF\Registration\Listen add
Key HKLM\SOFTWARE\Microsoft\Ole add
Key HKLM\SOFTWARE\Microsoft\PlayToReceiver add
Key HKLM\SOFTWARE\Microsoft\Security Center add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople add
Key HKLM\SOFTWARE\Microsoft\TabletTip\1.7 add
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Key HKLM\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.help add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.newfolder add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.properties add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.redo add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.rename add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.RibbonDelete add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.undo add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PerceptionSimulationExtensions add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore add
Key HKLM\SOFTWARE\Microsoft\Windows\Shell add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server add
Key HKLM\SOFTWARE\Policies add
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates add
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\WOW6432Node add
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder add
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder add
Key HKLM\SYSTEM\ControlSet001\Control\NetworkUxManager add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions add
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager add
Key HKLM\SYSTEM\ControlSet001\Services\crypt32 add
Key HKU add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Colors add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Desktop add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Control Panel\Keyboard add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\GameBar add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\MSF\Registration\Listen add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\TabletTip\1.7 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollection\Current add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.placeholdertilecollectionlocal\Current add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstarttilepropertiesmap\Current add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.localstartvolatiletilepropertiesmap\Current add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$de${acee881c-40d8-4c2f-b63e-fcc3351fd8e4}$$windows.data.unifiedtile.roamedtilepropertiesmap\Current add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.bluelightreductionstate\windows.data.bluelightreduction.bluelightreductionstate add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\BannerStore add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ModeTriggerCachedKey add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\VirtualDesktops add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{BCB48336-4DDD-48FF-BB0B-D3190DACB3E2}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}\Count add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\VirtualDesktops add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\GameDVR add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Holographic add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\SignalManager\Peek\CacheStore add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\Shell\Bags\1\Desktop add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\WorkFolders add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\39\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\66\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\68\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache add
Running Processes\lsass.exe\Opened Handles\ mod
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msprivs.dll.mui 2023-06-12 02:28.23 15,776 add
Running Processes\MicrosoftEdge.exe -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca\Opened Handles\ mod
File C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\~DF39C635ED25EB69E3.TMP 2026-10-07 02:08.29 0 old
File C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\~DF39C635ED25EB69E3.TMP 2026-10-07 02:08.45 16,384 new
Running Processes\ProcessHacker.exe\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dbgcore.dll 2019-03-19 07:44.35 157,696 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dbghelp.dll 2019-03-19 07:44.35 1,930,752 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\apphelp.dll 2019-03-19 07:44.28 564,736 add
Running Processes\ProcessHacker.exe\Opened Handles\ mod
File C:\Windows\System32\ru-RU\ntdll.dll.mui 2019-03-19 14:34.30 484,864 add
Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d add
File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui 2019-06-12 04:33.42 12,288 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion add
Running Processes\Procmon64.exe\ mod
Internet Explorer 11.0.18362.175 Microsoft Corporation c:\windows\system32\urlmon.dll 2019-06-12 04:33.44 1,853,440 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47langs.dll 2019-03-19 07:44.15 369,504 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47mrm.dll 2019-03-19 07:44.15 186,672 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cldapi.dll 2019-03-19 07:44.28 105,984 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coml2.dll 2019-03-19 07:44.15 477,240 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptbase.dll 2019-03-19 07:44.36 33,848 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\duser.dll 2019-03-19 07:44.47 578,560 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\globinputhost.dll 2019-03-19 07:44.15 130,560 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\linkinfo.dll 2019-03-19 07:44.30 30,720 add
Microsoft® Windows® Operating System 7.2.18362.1 Microsoft Corporation c:\windows\system32\oleacc.dll 2019-03-19 07:45.00 395,776 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sspicli.dll 2019-03-19 07:44.36 179,944 add
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\windows.globalization.dll 2019-06-12 04:33.37 1,784,832 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositoryps.dll 2019-03-19 07:44.15 1,274,336 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.storage.search.dll 2019-03-19 07:44.04 748,544 add
Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\structuredquery.dll 2019-03-19 07:44.15 676,840 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\program files\common files\microsoft shared\ink\tiptsf.dll 2019-03-19 07:45.49 659,464 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dui70.dll 2019-03-19 07:44.47 1,748,992 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\edputil.dll 2019-03-19 07:44.47 119,808 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ehstorshell.dll 2019-03-19 07:44.47 208,384 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\explorerframe.dll 2019-03-19 07:45.05 2,094,592 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\networkexplorer.dll 2019-03-19 07:44.48 76,288 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\setupapi.dll 2019-03-19 07:45.00 4,683,784 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\twinapi.dll 2019-03-19 07:44.33 636,416 add
Running Processes\Procmon64.exe\Opened Handles\ mod
File \FileSystem\Filters\FltMgrMsg add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc.dll.mui 2023-06-12 02:28.22 13,216 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc6.dll.mui 2023-06-12 02:28.22 39,832 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui 2023-06-12 02:28.22 37,792 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\napinsp.dll.mui 2023-06-12 02:28.23 13,216 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui 2023-06-12 02:28.23 30,616 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnrpnsp.dll.mui 2023-06-12 02:28.23 13,208 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wship6.dll.mui 2023-06-12 02:28.25 13,216 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshqos.dll.mui 2023-06-12 02:28.25 13,216 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshtcpip.dll.mui 2023-06-12 02:28.25 13,216 add
File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 2023-06-12 15:55.27 1,048,576 add
Directory C:\Users\user\Desktop\tools\ProcessMonitor old
Directory C:\Users\user\Desktop\tools\ProcessMonitor new
File C:\Windows\SystemResources\comdlg32.dll.mun 2019-03-19 07:45.05 352,768 add
File C:\Windows\SystemResources\ExplorerFrame.dll.mun 2019-03-19 07:45.05 2,640,896 add
File C:\Windows\SystemResources\shell32.dll.mun 2019-06-12 04:33.41 14,768,128 add
Key HKLM\SOFTWARE add
Key HKLM\SOFTWARE\Classes\CLSID\{088e3905-0323-4b02-9826-5d99428e115f}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{24ad3ad4-a569-4530-98e1-ab02f9417aa8}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{d3162b92-9365-467a-956b-92703aca08af}\Instance add
Key HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\Microsoft\Windows\Shell add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server add
Key HKLM\SOFTWARE\Policies add
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\WOW6432Node add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell add
Running Processes\rundll32.exe {638125B9-A355-4093-ADB2-B0299E77A4DB}.dbf, #1 #1\ add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64.dll 2019-03-19 07:44.38 335,752 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64cpu.dll 2019-03-19 07:44.38 20,728 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64win.dll 2019-03-19 07:44.38 510,488 add
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 add
Running Processes\rundll32.exe {638125B9-A355-4093-ADB2-B0299E77A4DB}.dbf, #1 #1\Opened Handles\ add
File \Device\CNG add
File \Device\DeviceApi add
File \Device\KsecDD add
File \Device\Nsi add
Directory \KnownDlls add
Directory \KnownDlls32 add
Directory \Sessions\1\BaseNamedObjects add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rundll32.exe.mui 2023-06-12 02:28.24 13,208 add
Directory C:\Users\user\AppData\Roaming\Microsoft add
Directory C:\Windows add
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 add
Key HKLM add
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust add
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople add
Key HKLM\SOFTWARE\Microsoft\Ole add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust add
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople add
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Key HKLM\SOFTWARE\Policies add
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates add
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\WOW6432Node add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder add
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions add
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager add
Key HKLM\SYSTEM\ControlSet001\Services\crypt32 add
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 add
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 add
Key HKU add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft add
Running Processes\RuntimeBroker.exe -Embedding\ mod
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\appresolver.dll 2019-03-19 07:44.21 558,344 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\slc.dll 2019-03-19 07:44.32 140,800 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\sppc.dll 2019-03-19 07:44.32 136,192 del
Running Processes\RuntimeBroker.exe -Embedding\ mod
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\iertutil.dll 2019-06-12 04:33.44 2,769,976 add
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\wininet.dll 2019-06-12 04:33.43 5,040,640 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47langs.dll 2019-03-19 07:44.15 369,504 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cfgmgr32.dll 2019-03-19 07:44.35 293,344 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coml2.dll 2019-03-19 07:44.15 477,240 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptsp.dll 2019-03-19 07:44.33 80,112 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\d3d11.dll 2019-03-19 07:44.11 2,466,296 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dxcore.dll 2019-03-19 07:44.06 112,296 add
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\dxgi.dll 2019-06-12 04:33.38 939,504 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\linkinfo.dll 2019-03-19 07:44.30 30,720 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\profapi.dll 2019-03-19 07:44.36 110,280 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\secur32.dll 2019-03-19 07:45.00 27,648 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositorycore.dll 2019-03-19 07:44.15 45,568 add
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 del
Windows Installer - Unicode 5.0.18362.175 Microsoft Corporation c:\windows\system32\msi.dll 2019-06-12 04:33.52 4,577,280 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\appresolver.dll 2019-03-19 07:44.21 558,344 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\capauthz.dll 2019-03-19 07:44.01 313,016 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mlang.dll 2019-03-19 07:44.58 245,760 add
Операционная система Microsoft® Windows® 10.0.18362.113 Microsoft Corporation c:\windows\system32\ole32.dll 2019-06-12 04:33.40 1,395,600 add
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\shell32.dll 2019-06-12 04:33.41 7,241,800 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shlwapi.dll 2019-03-19 07:45.05 329,200 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\slc.dll 2019-03-19 07:44.32 140,800 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\sppc.dll 2019-03-19 07:44.32 136,192 add
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\userenv.dll 2019-06-12 04:33.42 139,472 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\uxtheme.dll 2019-03-19 07:44.33 606,208 add
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\windows.internal.shell.broker.dll 2019-06-12 04:33.44 888,056 add
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\windows.storage.dll 2019-06-12 04:33.39 7,887,656 add
Операционная система Microsoft® Windows® 6.10.18362.175 Microsoft Corporation c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9\comctl32.dll 2019-06-12 04:33.44 2,624,824 add
Служба Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\propsys.dll 2019-03-19 07:44.15 977,680 add
Running Processes\RuntimeBroker.exe -Embedding\Opened Handles\ mod
File \Device\CNG del
File \Device\KsecDD del
Directory \KnownDlls del
Directory \Sessions\1\BaseNamedObjects del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKU del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft del
File \Device\CNG add
File \Device\DeviceApi add
File \Device\KsecDD add
Directory \KnownDlls add
Directory \Sessions\1\BaseNamedObjects add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 add
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 add
Directory C:\Windows\System32 add
File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 add
Directory C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9 add
Key HKLM add
Key HKLM\SOFTWARE add
Key HKLM\SOFTWARE\Classes add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main add
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security add
Key HKLM\SOFTWARE\Microsoft\Ole add
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server add
Key HKLM\SOFTWARE\Policies add
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKLM\SOFTWARE\WOW6432Node add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions add
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager add
Key HKU add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft add
Running Processes\RuntimeBroker.exe -Embedding\ mod
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\iertutil.dll 2019-06-12 04:33.44 2,769,976 del
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\wininet.dll 2019-06-12 04:33.43 5,040,640 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47langs.dll 2019-03-19 07:44.15 369,504 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cfgmgr32.dll 2019-03-19 07:44.35 293,344 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coml2.dll 2019-03-19 07:44.15 477,240 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptsp.dll 2019-03-19 07:44.33 80,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\d3d11.dll 2019-03-19 07:44.11 2,466,296 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dxcore.dll 2019-03-19 07:44.06 112,296 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\dxgi.dll 2019-06-12 04:33.38 939,504 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\linkinfo.dll 2019-03-19 07:44.30 30,720 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\profapi.dll 2019-03-19 07:44.36 110,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\secur32.dll 2019-03-19 07:45.00 27,648 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositorycore.dll 2019-03-19 07:44.15 45,568 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 add
Windows Installer - Unicode 5.0.18362.175 Microsoft Corporation c:\windows\system32\msi.dll 2019-06-12 04:33.52 4,577,280 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\appresolver.dll 2019-03-19 07:44.21 558,344 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\capauthz.dll 2019-03-19 07:44.01 313,016 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mlang.dll 2019-03-19 07:44.58 245,760 del
Операционная система Microsoft® Windows® 10.0.18362.113 Microsoft Corporation c:\windows\system32\ole32.dll 2019-06-12 04:33.40 1,395,600 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\shell32.dll 2019-06-12 04:33.41 7,241,800 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shlwapi.dll 2019-03-19 07:45.05 329,200 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\slc.dll 2019-03-19 07:44.32 140,800 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\sppc.dll 2019-03-19 07:44.32 136,192 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\userenv.dll 2019-06-12 04:33.42 139,472 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\uxtheme.dll 2019-03-19 07:44.33 606,208 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\windows.internal.shell.broker.dll 2019-06-12 04:33.44 888,056 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\windows.storage.dll 2019-06-12 04:33.39 7,887,656 del
Операционная система Microsoft® Windows® 6.10.18362.175 Microsoft Corporation c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9\comctl32.dll 2019-06-12 04:33.44 2,624,824 del
Служба Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\propsys.dll 2019-03-19 07:44.15 977,680 del
Running Processes\RuntimeBroker.exe -Embedding\Opened Handles\ mod
File \Device\CNG add
File \Device\KsecDD add
Directory \KnownDlls add
Directory \Sessions\1\BaseNamedObjects add
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 add
Directory C:\Windows\System32 add
Key HKLM add
Key HKLM\SOFTWARE\Classes add
Key HKLM\SOFTWARE\Microsoft\Ole add
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime add
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids add
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions add
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager add
Key HKU add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft add
File \Device\CNG del
File \Device\DeviceApi del
File \Device\KsecDD del
Directory \KnownDlls del
Directory \Sessions\1\BaseNamedObjects del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 del
Directory C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.175_none_e6c3ab1f131014c9 del
Key HKLM del
Key HKLM\SOFTWARE del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server del
Key HKLM\SOFTWARE\Policies del
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\WOW6432Node del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKU del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft del
Running Processes\SearchIndexer.exe /Embedding\Opened Handles\ mod
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx 2026-10-07 02:08.29 1,048,576 old
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx 2026-10-07 02:08.30 1,048,576 new
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr 2026-10-07 02:04.48 10,574 old
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr 2026-10-07 02:04.48 36,678 new
Running Processes\sihost.exe\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositoryps.dll 2019-03-19 07:44.15 1,274,336 del
Running Processes\smartscreen.exe -Embedding\ del
International Components for Unicode 63.1.0.0 The ICU Project c:\windows\system32\icu.dll 2019-06-12 04:33.39 2,321,408 del
International Components for Unicode 63.1.0.0 The ICU Project c:\windows\system32\icuin.dll 2019-03-19 07:44.15 25,088 del
International Components for Unicode 63.1.0.0 The ICU Project c:\windows\system32\icuuc.dll 2019-03-19 07:44.15 29,696 del
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\iertutil.dll 2019-06-12 04:33.44 2,769,976 del
Internet Explorer 11.0.18362.175 Microsoft Corporation c:\windows\system32\urlmon.dll 2019-06-12 04:33.44 1,853,440 del
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\wininet.dll 2019-06-12 04:33.43 5,040,640 del
Microsoft ® Chakra 11.0.18362.175 Microsoft Corporation c:\windows\system32\chakra.dll 2019-06-12 04:33.52 7,757,312 del
Microsoft® .NET Framework 4.8.3673.0 Microsoft Corporation c:\windows\system32\rometadata.dll 2019-03-19 07:44.06 234,432 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptbase.dll 2019-03-19 07:44.36 33,848 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptnet.dll 2019-03-19 07:44.33 168,448 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptsp.dll 2019-03-19 07:44.33 80,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dpapi.dll 2019-03-19 07:44.35 15,872 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dsparse.dll 2019-03-19 07:44.35 30,208 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\fwbase.dll 2019-03-19 07:44.15 162,304 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\imagehlp.dll 2019-03-19 07:44.35 108,936 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\imm32.dll 2019-03-19 07:44.38 176,360 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncryptsslp.dll 2019-03-19 07:44.35 134,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\netutils.dll 2019-03-19 07:44.35 40,784 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\nsi.dll 2019-03-19 07:44.36 25,000 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ntasn1.dll 2019-03-19 07:44.35 241,128 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\oleaut32.dll 2019-06-12 04:33.42 797,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ondemandconnroutehelper.dll 2019-03-19 07:44.00 73,216 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\profapi.dll 2019-03-19 07:44.36 110,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\rasadhlp.dll 2019-03-19 07:45.02 16,896 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\rsaenh.dll 2019-03-19 07:44.35 202,440 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\smartscreenps.dll 2019-03-19 07:44.03 256,000 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sspicli.dll 2019-03-19 07:44.36 179,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\tbs.dll 2019-03-19 07:43.54 48,048 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.security.authentication.onlineid.dll 2019-03-19 07:44.04 914,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\winnsi.dll 2019-03-19 07:44.36 34,808 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\winrttracing.dll 2019-03-19 07:44.01 189,952 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wkscli.dll 2019-03-19 07:44.35 80,600 del
umpdc.dll c:\windows\system32\umpdc.dll 2019-03-19 07:43.49 54,960 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\advapi32.dll 2019-03-19 07:43.54 655,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcrypt.dll 2019-03-19 07:44.33 144,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certca.dll 2019-03-19 07:44.04 807,424 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certenroll.dll 2019-03-19 07:44.06 3,184,128 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dnsapi.dll 2019-03-19 07:44.33 818,888 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\firewallapi.dll 2019-03-19 07:44.15 551,936 del
Операционная система Microsoft® Windows® 10.0.18362.113 Microsoft Corporation c:\windows\system32\fwpuclnt.dll 2019-06-12 04:33.39 467,456 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\iphlpapi.dll 2019-03-19 07:44.33 229,528 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mlang.dll 2019-03-19 07:44.58 245,760 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mskeyprotect.dll 2019-03-19 07:44.06 62,976 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mswsock.dll 2019-03-19 07:44.33 407,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncrypt.dll 2019-03-19 07:44.35 144,840 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\powrprof.dll 2019-03-19 07:44.35 291,336 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\schannel.dll 2019-06-12 04:33.42 537,088 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shcore.dll 2019-03-19 07:44.21 684,352 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shlwapi.dll 2019-03-19 07:45.05 329,200 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\uxtheme.dll 2019-03-19 07:44.33 606,208 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\windows.storage.dll 2019-06-12 04:33.39 7,887,656 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.web.http.dll 2019-03-19 07:44.01 1,498,624 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\winhttp.dll 2019-03-19 07:44.35 980,248 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wintypes.dll 2019-03-19 07:44.33 1,393,960 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wldap32.dll 2019-03-19 07:44.35 402,432 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ws2_32.dll 2019-03-19 07:44.36 443,424 del
Running Processes\smartscreen.exe -Embedding\Opened Handles\ del
File \Device\CNG del
File \Device\KsecDD del
File \Device\Nsi del
Directory \KnownDlls del
Directory \Sessions\1\BaseNamedObjects del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\smartscreen.exe.mui 2023-06-12 02:28.24 25,488 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.Http.dll.mui 2023-06-12 02:28.24 23,968 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
File C:\Windows\System32\WinMetadata\Windows.Foundation.winmd 2019-03-19 07:45.02 69,328 del
Key HKLM del
Key HKLM\SOFTWARE del
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SOFTWARE\Policies del
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\WOW6432Node del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKLM\SYSTEM\ControlSet001\Services\crypt32 del
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces del
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces del
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 del
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 del
Key HKU del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft del
Running Processes\svchost.exe -k appmodel -p -s camsvc\ del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\capabilityaccesshandlers.dll 2019-03-19 07:44.06 65,024 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\capabilityaccessmanagerclient.dll 2019-06-12 04:33.38 226,816 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cfgmgr32.dll 2019-03-19 07:44.35 293,344 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\devobj.dll 2019-03-19 07:44.35 158,592 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\oleaut32.dll 2019-06-12 04:33.42 797,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 del
umpdc.dll c:\windows\system32\umpdc.dll 2019-03-19 07:43.49 54,960 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\advapi32.dll 2019-03-19 07:43.54 655,144 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\audioses.dll 2019-06-12 04:33.35 1,413,704 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\capabilityaccessmanager.dll 2019-06-12 04:33.38 344,576 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mmdevapi.dll 2019-03-19 07:43.47 476,936 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\powrprof.dll 2019-03-19 07:44.35 291,336 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shcore.dll 2019-03-19 07:44.21 684,352 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wintypes.dll 2019-03-19 07:44.33 1,393,960 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\wldp.dll 2019-06-12 04:33.42 161,848 del
Running Processes\svchost.exe -k appmodel -p -s camsvc\Opened Handles\ del
Directory \BaseNamedObjects del
File \Device\CNG del
File \Device\DeviceApi del
Directory \KnownDlls del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui 2023-06-12 02:28.24 12,680 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKU\.DEFAULT\Software\Classes del
Key HKU\.DEFAULT\Software\Classes\Local Settings del
Key HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft del
Running Processes\svchost.exe -k appmodel -p -s StateRepository\ mod
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wintypes.dll 2019-03-19 07:44.33 1,393,960 del
Running Processes\svchost.exe -k appmodel -p -s StateRepository\Opened Handles\ mod
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd 2026-10-07 02:05.30 7,340,032 old
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd 2026-10-07 02:14.29 7,340,032 new
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm 2026-10-07 02:04.47 32,768 old
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm 2026-10-07 02:15.37 32,768 new
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal 2026-10-07 02:04.48 8,272 old
File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal 2026-10-07 02:14.29 0 new
Running Processes\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\onecorecommonproxystub.dll 2019-03-19 07:43.45 479,744 del
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog\Opened Handles\ mod
File C:\Windows\System32\winevt\Logs\microsoft-windows-diagnosis-scripted%4operational.evtx 2026-10-05 22:03.02 69,632 add
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc\ del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dpapi.dll 2019-03-19 07:44.35 15,872 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\imagehlp.dll 2019-03-19 07:44.35 108,936 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ktmw32.dll 2019-03-19 07:44.53 24,576 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\netutils.dll 2019-03-19 07:44.35 40,784 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnr.dll 2019-03-19 07:44.06 617,472 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnrgidshandler.dll 2019-03-19 07:44.38 488,448 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\profapi.dll 2019-03-19 07:44.36 110,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\samcli.dll 2019-03-19 07:44.35 78,848 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\tbs.dll 2019-03-19 07:43.54 48,048 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcrypt.dll 2019-03-19 07:44.33 144,144 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnrsvc.dll 2019-03-19 07:44.06 810,496 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\wldp.dll 2019-06-12 04:33.42 161,848 del
Running Processes\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc\Opened Handles\ del
Directory \BaseNamedObjects del
File \Device\CNG del
File \Device\KsecDD del
Directory \KnownDlls del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui 2023-06-12 02:28.24 12,680 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKU\S-1-5-19\Software\Classes del
Key HKU\S-1-5-19\Software\Classes\Local Settings del
Key HKU\S-1-5-19\Software\Classes\Local Settings\Software\Microsoft del
Running Processes\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 add
Running Processes\svchost.exe -k netsvcs -p -s TokenBroker\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coremessaging.dll 2019-03-19 07:44.30 859,632 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coreuicomponents.dll 2019-03-19 07:44.09 3,323,336 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\inputhost.dll 2019-03-19 07:44.12 1,052,096 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\textinputframework.dll 2019-03-19 07:44.11 642,216 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositorybroker.dll 2019-03-19 07:44.15 104,464 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.staterepositoryps.dll 2019-03-19 07:44.15 1,274,336 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.ui.dll 2019-03-19 07:44.00 1,383,648 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ntmarta.dll 2019-03-19 07:44.35 181,856 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\vaultcli.dll 2019-03-19 07:44.06 289,280 del
Running Processes\svchost.exe -k netsvcs -p -s UsoSvc\Opened Handles\ mod
File C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.f6523472-7654-4537-a3ef-11a4a1f3ca78.1.etl 2026-10-07 02:04.47 0 old
File C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.f6523472-7654-4537-a3ef-11a4a1f3ca78.1.etl 2026-10-07 02:04.47 4,096 new
Running Processes\svchost.exe -k netsvcs -p -s WpnService\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\coremessaging.dll 2019-03-19 07:44.30 859,632 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\staterepository.core.dll 2019-03-19 07:44.15 716,520 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\usermgrproxy.dll 2019-03-19 07:44.38 294,912 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.security.authentication.onlineid.dll 2019-03-19 07:44.04 914,944 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\appxdeploymentclient.dll 2019-06-12 04:33.39 909,736 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\execmodelclient.dll 2019-03-19 07:44.03 318,176 del
Running Processes\svchost.exe -k netsvcs -p -s WpnService\Opened Handles\ mod
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal 2026-10-07 01:40.40 3,687,432 old
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal 2026-10-07 02:06.46 3,720,392 new
Running Processes\svchost.exe -k netsvcs -p -s wuauserv\ del
Internet Explorer 11.0.18362.116 Microsoft Corporation c:\windows\system32\iertutil.dll 2019-06-12 04:33.44 2,769,976 del
Microsoft XML Core Services 6.30.18362.175 Microsoft Corporation c:\windows\system32\msxml6.dll 2019-06-12 04:33.38 2,449,456 del
Microsoft® Windows® Operating System 4.18.26080.4 Microsoft Corporation c:\programdata\microsoft\windows defender\platform\4.18.26080.4-0\mpoav.dll 2026-10-05 21:37.46 677,912 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\amsi.dll 2019-03-19 07:43.57 68,608 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcd.dll 2019-03-19 07:44.35 123,632 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47langs.dll 2019-03-19 07:44.15 369,504 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47mrm.dll 2019-03-19 07:44.15 186,672 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\biwinrt.dll 2019-03-19 07:44.06 308,376 del
Microsoft® Windows® Operating System 5.0.1.1 Microsoft Corporation c:\windows\system32\cabinet.dll 2019-03-19 07:44.30 146,200 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cfgmgr32.dll 2019-03-19 07:44.35 293,344 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\configmanager2.dll 2019-03-19 07:44.47 664,064 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptbase.dll 2019-03-19 07:44.36 33,848 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptnet.dll 2019-03-19 07:44.33 168,448 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptsp.dll 2019-03-19 07:44.33 80,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\defaultdevicemanager.dll 2019-03-19 07:44.47 21,392 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\devobj.dll 2019-03-19 07:44.35 158,592 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmcfgutils.dll 2019-03-19 07:44.47 108,032 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmcmnutils.dll 2019-03-19 07:44.47 161,672 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmenrollengine.dll 2019-03-19 07:44.47 611,328 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmiso8601utils.dll 2019-03-19 07:44.47 14,848 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmoleaututils.dll 2019-03-19 07:44.47 30,720 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmxmlhelputils.dll 2019-03-19 07:44.06 109,568 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dpapi.dll 2019-03-19 07:44.35 15,872 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dsparse.dll 2019-03-19 07:44.35 30,208 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dusmapi.dll 2019-03-19 07:45.32 48,640 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\enterprisecsps.dll 2019-03-19 07:44.47 1,815,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\enterpriseresourcemanager.dll 2019-03-19 07:44.47 84,480 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\iri.dll 2019-03-19 07:44.47 50,616 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp110_win.dll 2019-03-19 07:43.45 560,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\mswb7.dll 2019-03-19 07:43.57 257,184 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncryptsslp.dll 2019-03-19 07:44.35 134,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\netprofm.dll 2019-03-19 07:45.00 226,816 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\npmproxy.dll 2019-03-19 07:45.00 45,056 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\nsi.dll 2019-03-19 07:44.36 25,000 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ntasn1.dll 2019-03-19 07:44.35 241,128 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\oleaut32.dll 2019-06-12 04:33.42 797,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\omadmapi.dll 2019-03-19 07:44.47 164,776 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\onecorecommonproxystub.dll 2019-03-19 07:43.45 479,744 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\policymanager.dll 2019-03-19 07:44.47 514,424 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\productenumerator.dll 2019-03-19 07:44.06 36,352 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\profapi.dll 2019-03-19 07:44.36 110,280 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\rasadhlp.dll 2019-03-19 07:45.02 16,896 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\resourcepolicyclient.dll 2019-03-19 07:44.04 70,256 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\rsaenh.dll 2019-03-19 07:44.35 202,440 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sspicli.dll 2019-03-19 07:44.36 179,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\storewuauth.dll 2019-03-19 07:44.15 277,504 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\version.dll 2019-03-19 07:45.05 30,680 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\fastprox.dll 2019-03-19 07:43.54 1,031,680 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemprox.dll 2019-03-19 07:43.54 44,544 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemsvc.dll 2019-03-19 07:43.54 63,488 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbemcomn.dll 2019-03-19 07:43.54 487,424 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.devices.enumeration.dll 2019-03-19 07:44.04 523,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.devices.sensors.dll 2019-03-19 07:44.53 1,284,232 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\windows.globalization.dll 2019-06-12 04:33.37 1,784,832 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.graphics.dll 2019-03-19 07:44.06 525,824 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.networking.connectivity.dll 2019-03-19 07:44.00 767,488 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.security.authentication.onlineid.dll 2019-03-19 07:44.04 914,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\winnsi.dll 2019-03-19 07:44.36 34,808 del
Microsoft® Windows® Operating System 10.0.18362.53 Microsoft Corporation c:\windows\system32\winsta.dll 2019-06-12 04:33.42 358,944 del
Microsoft® Windows® Operating System 10.0.18362.145 Microsoft Corporation c:\windows\system32\wintrust.dll 2019-06-12 04:33.39 363,624 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wtsapi32.dll 2019-03-19 07:44.33 64,792 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wups.dll 2019-03-19 07:44.06 70,144 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuuhext.dll 2019-03-19 07:44.38 497,664 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuuhosdeployment.dll 2019-03-19 07:44.06 207,872 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\xmllite.dll 2019-03-19 07:44.38 211,216 del
umpdc.dll c:\windows\system32\umpdc.dll 2019-03-19 07:43.49 54,960 del
Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\structuredquery.dll 2019-03-19 07:44.15 676,840 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\advapi32.dll 2019-03-19 07:43.54 655,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcrypt.dll 2019-03-19 07:44.33 144,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certca.dll 2019-03-19 07:44.04 807,424 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certenroll.dll 2019-03-19 07:44.06 3,184,128 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ddores.dll 2019-03-19 07:44.47 47,512 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\devdispitemprovider.dll 2019-03-19 07:44.04 119,328 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dhcpcsvc.dll 2019-03-19 07:44.33 92,672 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dhcpcsvc6.dll 2019-03-19 07:44.33 68,096 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmenterprisediagnostics.dll 2019-03-19 07:44.47 314,880 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dnsapi.dll 2019-03-19 07:44.33 818,888 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\esent.dll 2019-03-19 07:44.15 3,261,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\flightsettings.dll 2019-03-19 07:43.50 892,928 del
Операционная система Microsoft® Windows® 10.0.18362.113 Microsoft Corporation c:\windows\system32\fwpuclnt.dll 2019-06-12 04:33.39 467,456 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\gpapi.dll 2019-03-19 07:44.48 129,808 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\iphlpapi.dll 2019-03-19 07:44.33 229,528 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mskeyprotect.dll 2019-03-19 07:44.06 62,976 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\mswsock.dll 2019-03-19 07:44.33 407,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncrypt.dll 2019-03-19 07:44.35 144,840 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.113 Microsoft Corporation c:\windows\system32\ole32.dll 2019-06-12 04:33.40 1,395,600 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\powrprof.dll 2019-03-19 07:44.35 291,336 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\schannel.dll 2019-06-12 04:33.42 537,088 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shcore.dll 2019-03-19 07:44.21 684,352 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\shlwapi.dll 2019-03-19 07:45.05 329,200 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\updatepolicy.dll 2019-03-19 07:44.06 200,192 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\userenv.dll 2019-06-12 04:33.42 139,472 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\vaultcli.dll 2019-03-19 07:44.06 289,280 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\webio.dll 2019-03-19 07:44.35 598,016 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\webservices.dll 2019-03-19 07:44.15 1,379,248 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wevtapi.dll 2019-03-19 07:44.18 379,128 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.security.authentication.web.core.dll 2019-03-19 07:44.03 1,166,848 del
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\windows.storage.dll 2019-06-12 04:33.39 7,887,656 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.web.dll 2019-03-19 07:44.01 758,784 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\winhttp.dll 2019-03-19 07:44.35 980,248 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wintypes.dll 2019-03-19 07:44.33 1,393,960 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wldap32.dll 2019-03-19 07:44.35 402,432 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\wldp.dll 2019-06-12 04:33.42 161,848 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wosc.dll 2019-03-19 07:43.45 242,688 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ws2_32.dll 2019-03-19 07:44.36 443,424 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuapi.dll 2019-03-19 07:44.06 841,216 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuaueng.dll 2019-03-19 07:44.06 3,104,768 del
Служба Windows® Search 7.0.18362.1 Microsoft Corporation c:\windows\system32\propsys.dll 2019-03-19 07:44.15 977,680 del
Running Processes\svchost.exe -k netsvcs -p -s wuauserv\Opened Handles\ del
Directory \BaseNamedObjects del
File \Device\Afd del
File \Device\CNG del
File \Device\DeviceApi del
File \Device\Harddisk0\DR0 del
File \Device\KsecDD del
File \Device\Nsi del
Directory \KnownDlls del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\svchost.exe.mui 2023-06-12 02:28.24 12,680 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.dll.mui 2023-06-12 02:28.24 181,664 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winnlsres.dll.mui 2023-06-12 02:28.24 78,240 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
File C:\Windows\SoftwareDistribution\DataStore\DataStore.edb 2026-10-07 02:06.46 36,700,160 del
File C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm 2026-10-07 02:06.46 16,384 del
File C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log 2026-10-07 02:06.46 1,310,720 del
File C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb 2026-10-07 02:12.57 262,144 del
File C:\Windows\SoftwareDistribution\ReportingEvents.log 2026-10-06 22:17.50 399,248 del
Directory C:\Windows\System32 del
File C:\Windows\System32\ru-RU\ESENT.dll.mui 2019-03-19 14:34.15 150,528 del
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
Directory C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust del
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust del
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache.v2\Legacy del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server del
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates del
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKLM\SYSTEM\ControlSet001\Services\crypt32 del
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces del
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces del
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 del
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 del
Key HKU\.DEFAULT del
Key HKU\.DEFAULT\Control Panel\International del
Key HKU\.DEFAULT\Software\Classes del
Key HKU\.DEFAULT\Software\Classes\Local Settings del
Key HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust del
Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople del
Key HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates del
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Running Processes\svchost.exe -k NetworkService -p -s CryptSvc\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cryptnet.dll 2019-03-19 07:44.33 168,448 add
Running Processes\svchost.exe -k NetworkService -p -s CryptSvc\Opened Handles\ mod
Directory C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData add
Running Processes\svchost.exe -k UnistackSvcGroup -s CDPUserSvc\Opened Handles\ mod
File C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal 2026-10-07 02:05.11 3,135,352 old
File C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal 2026-10-07 02:12.23 3,510,272 new
Running Processes\svchost.exe -k UnistackSvcGroup -s WpnUserService\Opened Handles\ mod
File C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal 2026-10-07 01:56.26 1,058,872 old
File C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-wal 2026-10-07 02:08.34 1,347,272 new
Running Processes\SysTracer.exe\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcp47langs.dll 2019-03-19 07:44.15 369,504 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\linkinfo.dll 2019-03-19 07:44.30 30,720 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\nsi.dll 2019-03-19 07:44.36 25,000 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\appresolver.dll 2019-03-19 07:44.21 558,344 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\slc.dll 2019-03-19 07:44.32 140,800 add
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\sppc.dll 2019-03-19 07:44.32 136,192 add
Операционная система Microsoft® Windows® 10.0.18362.175 Microsoft Corporation c:\windows\system32\userenv.dll 2019-06-12 04:33.42 139,472 add
Running Processes\SysTracer.exe\Opened Handles\ mod
File \Device\Nsi add
File C:\ del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\advapi32.dll.mui 2023-06-12 02:28.22 14,216 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\apphelp.dll.mui 2023-06-12 02:28.22 13,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bcrypt.dll.mui 2023-06-12 02:28.22 13,720 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\comdlg32.dll.mui 2023-06-12 02:28.22 70,552 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\d2d1.dll.mui 2023-06-12 02:28.22 301,456 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\DWrite.dll.mui 2023-06-12 02:28.22 12,680 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iertutil.dll.mui 2023-06-12 02:28.23 13,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iphlpapi.dll.mui 2023-06-12 02:28.23 14,240 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\jscript9.dll.mui 2023-06-12 02:28.23 45,984 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mlang.dll.mui 2023-06-12 02:28.23 28,064 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msctf.dll.mui 2023-06-12 02:28.23 14,736 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msimtf.dll.mui 2023-06-12 02:28.23 12,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ntmarta.dll.mui 2023-06-12 02:28.23 17,296 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oledlg.dll.mui 2023-06-12 02:28.23 40,328 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\powrprof.dll.mui 2023-06-12 02:28.24 80,784 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rpcrt4.dll.mui 2023-06-12 02:28.24 32,664 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\SHCore.dll.mui 2023-06-12 02:28.24 12,696 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\shlwapi.dll.mui 2023-06-12 02:28.24 14,752 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinapi.appcore.dll.mui 2023-06-12 02:28.24 17,800 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIAutomationCore.dll.mui 2023-06-12 02:28.24 30,096 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\uxtheme.dll.mui 2023-06-12 02:28.24 18,824 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winhttp.dll.mui 2023-06-12 02:28.24 31,120 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wininet.dll.mui 2023-06-12 02:28.24 44,944 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wintypes.dll.mui 2023-06-12 02:28.24 12,704 add
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wldp.dll.mui 2023-06-12 02:28.24 17,312 add
File C:\Users\user\Desktop\tools\SysTracer x64\data\snap-0.tmp 2026-10-07 02:13.47 0 del
File C:\Users\user\Desktop\tools\SysTracer x64\data\snap-1.tmp 2026-10-07 02:30.25 0 add
Directory C:\Windows del
File C:\Windows\System32\en-US\sechost.dll.mui 2019-03-19 14:34.30 2,560 add
File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 add
File C:\Windows\System32\ru-RU\kernel32.dll.mui 2019-03-19 14:34.33 1,042,944 add
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 add
File C:\Windows\System32\ru-RU\ntdll.dll.mui 2019-03-19 14:34.30 484,864 add
File C:\Windows\System32\ru-RU\ole32.dll.mui 2019-03-19 14:34.30 31,232 add
File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 add
File C:\Windows\System32\ru-RU\srpapi.dll.mui 2019-03-19 14:34.30 8,704 add
File C:\Windows\System32\ru-RU\winspool.drv.mui 2019-03-19 14:34.27 84,480 add
File C:\Windows\System32\ru-RU\ws2_32.dll.mui 2019-03-19 14:34.30 24,576 add
Directory C:\Windows\WinSxS del
Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34 add
File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34\comctl32.dll.mui 2019-06-12 04:33.42 6,144 add
Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d add
File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui 2019-06-12 04:33.42 12,288 add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
Key HKLM\SOFTWARE\WOW6432Node\Classes add
Key HKLM\SOFTWARE\WOW6432Node\Clients add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cellular add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\COM3 add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Current add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Readers add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\SystemShared add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\DeviceReg add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\DFS add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Driver Signing add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\EnterpriseCertificates add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\EventSystem add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\FingerKB add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\FuzzyDS add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Input add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\LanguageOverlay add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Messaging add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MSMQ add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFFuzzyFactors add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFInputType add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFKeyboardMappings add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Non-Driver Signing add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Notepad\DefaultFonts add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Ole add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Phone add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Pim add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Poom add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Ras add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Rpc add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Semgr add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Shell add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Software\Microsoft\Shared Tools\Msinfo add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\TermServLicensing add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Transaction Server add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Unified Store add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\UserData add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Console add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Containers add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontDPI add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontLink add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontMapper add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Fonts add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontSubstitutes add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\LanguagePack add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\NetworkCards add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Ports add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Print add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows Search add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Theme add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\ThemeVolatile add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Group Policy add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Parental Controls add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PreviewHandlers add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Telephony\Locations add
Key HKLM\SOFTWARE\WOW6432Node\Microsoft\XAML add
Key HKLM\SOFTWARE\WOW6432Node\Policies add
Key HKLM\SOFTWARE\WOW6432Node\RegisteredApplications add
Key HKLM\SYSTEM\ControlSet001\Control\Print\Printers add
Key HKLM\SYSTEM\ControlSet001\Control\Video\{7C8C3757-C0DF-11F1-B68A-806E6F6E6963}\0000 add
Key HKLM\SYSTEM\ControlSet001\Hardware Profiles\Current add
Key HKLM\SYSTEM\CurrentControlSet add
Key HKLM\SYSTEM\HardwareConfig\Current add
Key HKU del
Key HKU\S-1-5-18 add
Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Running Processes\wmiprvse.exe\ del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\cfgmgr32.dll 2019-03-19 07:44.35 293,344 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\devobj.dll 2019-03-19 07:44.35 158,592 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dxcore.dll 2019-03-19 07:44.06 112,296 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\framedynos.dll 2019-03-19 07:43.54 305,664 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\imagehlp.dll 2019-03-19 07:44.35 108,936 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msasn1.dll 2019-03-19 07:44.35 63,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncobjapi.dll 2019-03-19 07:43.54 73,728 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ntasn1.dll 2019-03-19 07:44.35 241,128 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\oleaut32.dll 2019-06-12 04:33.42 797,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sspicli.dll 2019-03-19 07:44.36 179,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\tbs.dll 2019-03-19 07:43.54 48,048 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\fastprox.dll 2019-03-19 07:43.54 1,031,680 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemprox.dll 2019-03-19 07:43.54 44,544 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemsvc.dll 2019-03-19 07:43.54 63,488 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\win32_tpm.dll 2019-03-19 07:43.54 79,360 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbemcomn.dll 2019-03-19 07:43.54 487,424 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.53 Microsoft Corporation c:\windows\system32\winsta.dll 2019-06-12 04:33.42 358,944 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wtsapi32.dll 2019-03-19 07:44.33 64,792 del
umpdc.dll c:\windows\system32\umpdc.dll 2019-03-19 07:43.49 54,960 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\advapi32.dll 2019-03-19 07:43.54 655,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcrypt.dll 2019-03-19 07:44.33 144,144 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\crypt32.dll 2019-03-19 07:44.33 1,326,856 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncrypt.dll 2019-03-19 07:44.35 144,840 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\powrprof.dll 2019-03-19 07:44.35 291,336 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\tpmcoreprovisioning.dll 2019-03-19 07:43.54 1,092,096 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\cimwin32.dll 2019-03-19 07:44.00 2,054,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wmiutils.dll 2019-03-19 07:43.54 131,584 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\winhttp.dll 2019-03-19 07:44.35 980,248 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ws2_32.dll 2019-03-19 07:44.36 443,424 del
Running Processes\wmiprvse.exe\Opened Handles\ del
Directory \BaseNamedObjects del
File \Device\CNG del
File \Device\DeviceApi del
File \Device\KsecDD del
Directory \KnownDlls del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui 2023-06-12 02:28.24 29,576 del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\wbem\ru-RU\cimwin32.dll.mui 2023-06-12 02:28.25 20,888 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Running Processes\wmiprvse.exe\ del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\bcryptprimitives.dll 2019-06-12 04:33.43 529,072 del
Microsoft® Windows® Operating System 2001.12.10941.16384 Microsoft Corporation c:\windows\system32\clbcatq.dll 2019-03-19 07:44.30 643,752 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\gdi32.dll 2019-03-19 07:44.06 147,912 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\gdi32full.dll 2019-06-12 04:33.43 1,647,584 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\kernel.appcore.dll 2019-03-19 07:44.15 59,088 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\msvcp_win.dll 2019-03-19 07:44.33 639,632 del
Microsoft® Windows® Operating System 7.0.18362.1 Microsoft Corporation c:\windows\system32\msvcrt.dll 2019-03-19 07:44.35 638,072 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ncobjapi.dll 2019-03-19 07:43.54 73,728 del
Microsoft® Windows® Operating System 10.0.18362.86 Microsoft Corporation c:\windows\system32\oleaut32.dll 2019-06-12 04:33.42 797,112 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\sechost.dll 2019-03-19 07:44.36 606,104 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ucrtbase.dll 2019-03-19 07:44.33 1,020,776 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\esscli.dll 2019-03-19 07:43.54 468,992 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\fastprox.dll 2019-03-19 07:43.54 1,031,680 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemprox.dll 2019-03-19 07:43.54 44,544 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wbemsvc.dll 2019-03-19 07:43.54 63,488 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wmiprov.dll 2019-03-19 07:44.00 218,624 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbemcomn.dll 2019-03-19 07:43.54 487,424 del
Microsoft® Windows® Operating System 10.0.18362.175 Microsoft Corporation c:\windows\system32\win32u.dll 2019-06-12 04:33.39 127,064 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wmiclnt.dll 2019-03-19 07:43.45 46,592 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\advapi32.dll 2019-03-19 07:43.54 655,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\bcrypt.dll 2019-03-19 07:44.33 144,144 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\combase.dll 2019-06-12 04:33.42 3,373,256 del
Операционная система Microsoft® Windows® 10.0.18362.86 Microsoft Corporation c:\windows\system32\kernel32.dll 2019-06-12 04:33.37 722,072 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\kernelbase.dll 2019-06-12 04:33.43 2,763,312 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\ntdll.dll 2019-06-12 04:33.42 1,999,440 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ntmarta.dll 2019-03-19 07:44.35 181,856 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\rpcrt4.dll 2019-03-19 07:44.36 1,171,192 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\user32.dll 2019-03-19 07:44.15 1,654,544 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wmiutils.dll 2019-03-19 07:43.54 131,584 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ws2_32.dll 2019-03-19 07:44.36 443,424 del
Running Processes\wmiprvse.exe\Opened Handles\ del
Directory \BaseNamedObjects del
File \Device\CNG del
File \Device\KsecDD del
File \Device\WMIDataDevice del
Directory \KnownDlls del
File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui 2023-06-12 02:28.24 29,576 del
File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Directory C:\Windows\System32 del
File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 del
File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
Key HKLM del
Key HKLM\SOFTWARE\Classes del
Key HKLM\SOFTWARE\Classes\PackagedCom del
Key HKLM\SOFTWARE\Microsoft\Ole del
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Key HKU\.DEFAULT\Software\Classes del
Key HKU\.DEFAULT\Software\Classes\Local Settings del
Key HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft del
Loaded Dlls\ mod
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\capabilityaccesshandlers.dll 2019-03-19 07:44.06 65,024 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\configmanager2.dll 2019-03-19 07:44.47 664,064 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\defaultdevicemanager.dll 2019-03-19 07:44.47 21,392 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmiso8601utils.dll 2019-03-19 07:44.47 14,848 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmoleaututils.dll 2019-03-19 07:44.47 30,720 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\enterprisecsps.dll 2019-03-19 07:44.47 1,815,040 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\enterpriseresourcemanager.dll 2019-03-19 07:44.47 84,480 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ktmw32.dll 2019-03-19 07:44.53 24,576 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnr.dll 2019-03-19 07:44.06 617,472 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnrgidshandler.dll 2019-03-19 07:44.38 488,448 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\productenumerator.dll 2019-03-19 07:44.06 36,352 del
Microsoft® Windows® Operating System 4.18.1901.16384 Microsoft Corporation c:\windows\system32\securityhealthproxystub.dll 2019-03-19 07:44.39 106,296 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\smartscreenps.dll 2019-03-19 07:44.03 256,000 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\storewuauth.dll 2019-03-19 07:44.15 277,504 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\win32_tpm.dll 2019-03-19 07:43.54 79,360 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\wmiprov.dll 2019-03-19 07:44.00 218,624 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\windows.devices.sensors.dll 2019-03-19 07:44.53 1,284,232 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\winrttracing.dll 2019-03-19 07:44.01 189,952 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64.dll 2019-03-19 07:44.38 335,752 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64cpu.dll 2019-03-19 07:44.38 20,728 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wow64win.dll 2019-03-19 07:44.38 510,488 add
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuuhext.dll 2019-03-19 07:44.38 497,664 del
Microsoft® Windows® Operating System 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuuhosdeployment.dll 2019-03-19 07:44.06 207,872 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\authui.dll 2019-03-19 07:44.00 261,120 del
Операционная система Microsoft® Windows® 10.0.18362.145 Microsoft Corporation c:\windows\system32\capabilityaccessmanager.dll 2019-06-12 04:33.38 344,576 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certca.dll 2019-03-19 07:44.04 807,424 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\certenroll.dll 2019-03-19 07:44.06 3,184,128 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ddores.dll 2019-03-19 07:44.47 47,512 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\dmenterprisediagnostics.dll 2019-03-19 07:44.47 314,880 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ehstorapi.dll 2019-03-19 07:45.38 132,096 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\ngcctnrsvc.dll 2019-03-19 07:44.06 810,496 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\tpmcoreprovisioning.dll 2019-03-19 07:43.54 1,092,096 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wbem\cimwin32.dll 2019-03-19 07:44.00 2,054,144 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wosc.dll 2019-03-19 07:43.45 242,688 del
Операционная система Microsoft® Windows® 10.0.18362.1 Microsoft Corporation c:\windows\system32\wuaueng.dll 2019-03-19 07:44.06 3,104,768 del
Opened Handles\ mod
Microsoft® Windows® Operating System C:\Windows\system32\lsass.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msprivs.dll.mui 2023-06-12 02:28.23 15,776 add
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Directory \BaseNamedObjects del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File \Device\CNG del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File \Device\DeviceApi del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File \Device\KsecDD del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File \Device\WMIDataDevice del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Directory \KnownDlls del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\user32.dll.mui 2023-06-12 02:28.24 29,576 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\wbem\ru-RU\cimwin32.dll.mui 2023-06-12 02:28.25 20,888 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Directory C:\Windows\System32 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SOFTWARE\Classes del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SOFTWARE\Classes\PackagedCom del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SOFTWARE\Microsoft\Ole del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKU\.DEFAULT\Software\Classes del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKU\.DEFAULT\Software\Classes\Local Settings del
Microsoft® Windows® Operating System C:\Windows\system32\wbem\wmiprvse.exe Key HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft del
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File \Device\CNG add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File \Device\DeviceApi add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File \Device\KsecDD add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File \Device\Nsi add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Directory \KnownDlls add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Directory \KnownDlls32 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Directory \Sessions\1\BaseNamedObjects add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rundll32.exe.mui 2023-06-12 02:28.24 13,208 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Directory C:\Users\user\AppData\Roaming\Microsoft add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Directory C:\Windows add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\Ole add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Policies add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ProviderOrder add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Control\Session Manager add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Services\crypt32 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings add
Microsoft® Windows® Operating System C:\Windows\SysWOW64\rundll32.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft add
Process Hacker C:\Program Files\Process Hacker 2\ProcessHacker.exe File C:\Windows\System32\ru-RU\ntdll.dll.mui 2019-03-19 14:34.30 484,864 add
Process Hacker C:\Program Files\Process Hacker 2\ProcessHacker.exe Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d add
Process Hacker C:\Program Files\Process Hacker 2\ProcessHacker.exe File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui 2019-06-12 04:33.42 12,288 add
Process Hacker C:\Program Files\Process Hacker 2\ProcessHacker.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows NT\CurrentVersion add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File \FileSystem\Filters\FltMgrMsg add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc.dll.mui 2023-06-12 02:28.22 13,216 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\dhcpcsvc6.dll.mui 2023-06-12 02:28.22 39,832 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\explorerframe.dll.mui 2023-06-12 02:28.22 37,792 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\napinsp.dll.mui 2023-06-12 02:28.23 13,216 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oleaccrc.dll.mui 2023-06-12 02:28.23 30,616 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\pnrpnsp.dll.mui 2023-06-12 02:28.23 13,208 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wship6.dll.mui 2023-06-12 02:28.25 13,216 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshqos.dll.mui 2023-06-12 02:28.25 13,216 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wshtcpip.dll.mui 2023-06-12 02:28.25 13,216 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 2023-06-12 15:55.27 1,048,576 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Directory C:\Users\user\Desktop\tools\ProcessMonitor old
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Directory C:\Users\user\Desktop\tools\ProcessMonitor new
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Windows\SystemResources\comdlg32.dll.mun 2019-03-19 07:45.05 352,768 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Windows\SystemResources\ExplorerFrame.dll.mun 2019-03-19 07:45.05 2,640,896 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe File C:\Windows\SystemResources\shell32.dll.mun 2019-06-12 04:33.41 14,768,128 add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{088e3905-0323-4b02-9826-5d99428e115f}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{24ad3ad4-a569-4530-98e1-ab02f9417aa8}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{374DE290-123F-4565-9164-39C4925E467B}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{d3162b92-9365-467a-956b-92703aca08af}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\Windows\Shell add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\WindowsRuntime add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Policies add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKLM\SOFTWARE\WOW6432Node add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell add
Sysinternals Procmon C:\Users\user\Desktop\tools\ProcessMonitor\Procmon64.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File \Device\Nsi add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\ del
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\advapi32.dll.mui 2023-06-12 02:28.22 14,216 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\apphelp.dll.mui 2023-06-12 02:28.22 13,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\bcrypt.dll.mui 2023-06-12 02:28.22 13,720 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\comdlg32.dll.mui 2023-06-12 02:28.22 70,552 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\d2d1.dll.mui 2023-06-12 02:28.22 301,456 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\DWrite.dll.mui 2023-06-12 02:28.22 12,680 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iertutil.dll.mui 2023-06-12 02:28.23 13,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\iphlpapi.dll.mui 2023-06-12 02:28.23 14,240 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\jscript9.dll.mui 2023-06-12 02:28.23 45,984 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mlang.dll.mui 2023-06-12 02:28.23 28,064 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msctf.dll.mui 2023-06-12 02:28.23 14,736 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\msimtf.dll.mui 2023-06-12 02:28.23 12,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\ntmarta.dll.mui 2023-06-12 02:28.23 17,296 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\oledlg.dll.mui 2023-06-12 02:28.23 40,328 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\powrprof.dll.mui 2023-06-12 02:28.24 80,784 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\propsys.dll.mui 2023-06-12 02:28.24 94,112 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\rpcrt4.dll.mui 2023-06-12 02:28.24 32,664 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\SHCore.dll.mui 2023-06-12 02:28.24 12,696 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\shlwapi.dll.mui 2023-06-12 02:28.24 14,752 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\twinapi.appcore.dll.mui 2023-06-12 02:28.24 17,800 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\UIAutomationCore.dll.mui 2023-06-12 02:28.24 30,096 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\uxtheme.dll.mui 2023-06-12 02:28.24 18,824 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\windows.storage.dll.mui 2023-06-12 02:28.24 40,864 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\winhttp.dll.mui 2023-06-12 02:28.24 31,120 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wininet.dll.mui 2023-06-12 02:28.24 44,944 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wintypes.dll.mui 2023-06-12 02:28.24 12,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\wldp.dll.mui 2023-06-12 02:28.24 17,312 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Users\user\Desktop\tools\SysTracer x64\data\snap-0.tmp 2026-10-07 02:14.00 6,306,356 del
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Users\user\Desktop\tools\SysTracer x64\data\snap-1.tmp 2026-10-07 02:30.43 22,162,357 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Directory C:\Windows del
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\en-US\sechost.dll.mui 2019-03-19 14:34.30 2,560 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\combase.dll.mui 2019-03-19 14:34.30 40,960 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\kernel32.dll.mui 2019-03-19 14:34.33 1,042,944 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\ntdll.dll.mui 2019-03-19 14:34.30 484,864 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\ole32.dll.mui 2019-03-19 14:34.30 31,232 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\shell32.dll.mui 2019-03-19 14:34.32 478,720 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\srpapi.dll.mui 2019-03-19 14:34.30 8,704 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\winspool.drv.mui 2019-03-19 14:34.27 84,480 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\System32\ru-RU\ws2_32.dll.mui 2019-03-19 14:34.30 24,576 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Directory C:\Windows\WinSxS del
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.18362.175_ru-ru_89567a6fc412ca34\comctl32.dll.mui 2019-06-12 04:33.42 6,144 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Directory C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe File C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.18362.175_ru-ru_45f00bb890bb425d\comctl32.dll.mui 2019-06-12 04:33.42 12,288 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Classes add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Clients add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cellular add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\COM3 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Current add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Calais\Readers add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\SystemShared add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\DeviceReg add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\DFS add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Driver Signing add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\EnterpriseCertificates add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\EventSystem add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\FingerKB add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\FuzzyDS add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Input add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\LanguageOverlay add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Messaging add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MSMQ add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFFuzzyFactors add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFInputType add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\MTFKeyboardMappings add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Non-Driver Signing add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Notepad\DefaultFonts add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Ole add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Phone add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Pim add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Poom add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Ras add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Rpc add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\SecurityManager add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Semgr add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Shell add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Software\Microsoft\Shared Tools\Msinfo add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\TermServLicensing add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Transaction Server add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Unified Store add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\UserData add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Console add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Containers add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontDPI add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontLink add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontMapper add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Fonts add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\FontSubstitutes add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\LanguagePack add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\NetworkCards add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Ports add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Print add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows Search add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\Theme add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Control Panel\ThemeVolatile add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Group Policy add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Parental Controls add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PreviewHandlers add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Telephony\Locations add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Microsoft\XAML add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\Policies add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SOFTWARE\WOW6432Node\RegisteredApplications add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SYSTEM\ControlSet001\Control\Print\Printers add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SYSTEM\ControlSet001\Control\Video\{7C8C3757-C0DF-11F1-B68A-806E6F6E6963}\0000 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SYSTEM\ControlSet001\Hardware Profiles\Current add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SYSTEM\CurrentControlSet add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKLM\SYSTEM\HardwareConfig\Current add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKU del
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKU\S-1-5-18 add
SysTracer v2.10 C:\Users\user\Desktop\tools\SysTracer x64\SysTracer.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts add
Операционная система Microsoft® Windows® C:\Windows\Explorer.EXE Directory C:\Users\user\Desktop\lab1\src old
Операционная система Microsoft® Windows® C:\Windows\Explorer.EXE Directory C:\Users\user\Desktop\lab1\src new
Операционная система Microsoft® Windows® C:\Windows\Explorer.EXE File C:\Windows\System32\ru-RU\ieframe.dll.mui 2019-03-19 14:34.16 1,805,824 add
Операционная система Microsoft® Windows® C:\Windows\Explorer.EXE Key HKLM\SOFTWARE\Classes del
Операционная система Microsoft® Windows® C:\Windows\Explorer.EXE Key HKLM\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance add
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File \Device\CNG del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File \Device\KsecDD del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File \Device\Nsi del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Directory \KnownDlls del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Directory \Sessions\1\BaseNamedObjects del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\crypt32.dll.mui 2023-06-12 02:28.22 55,704 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\mswsock.dll.mui 2023-06-12 02:28.23 23,968 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\smartscreen.exe.mui 2023-06-12 02:28.24 25,488 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.Http.dll.mui 2023-06-12 02:28.24 23,968 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Windows\Registration\R000000000006.clb 2023-06-12 00:13.07 27,356 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Directory C:\Windows\System32 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Windows\System32\ru-RU\KernelBase.dll.mui 2019-03-19 14:34.31 1,342,464 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe File C:\Windows\System32\WinMetadata\Windows.Foundation.winmd 2019-03-19 07:45.02 69,328 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Internet Explorer\Security del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Ole del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\WindowsRuntime del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Policies del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SOFTWARE\WOW6432Node del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Control\Session Manager del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Services\crypt32 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001 del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Internet Explorer\Security del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Explorer del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings del
Операционная система Microsoft® Windows® C:\Windows\System32\smartscreen.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001_Classes\Local Settings\Software\Microsoft del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_18362.49.138.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\Windows.Web.dll.mui 2023-06-12 02:28.24 181,664 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd 2026-10-07 02:05.30 7,340,032 old
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd 2026-10-07 02:14.29 7,340,032 new
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm 2026-10-07 02:04.47 32,768 old
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm 2026-10-07 02:15.37 32,768 new
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal 2026-10-07 02:04.48 8,272 old
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal 2026-10-07 02:14.29 0 new
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal 2026-10-07 02:12.23 3,510,272 old
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal 2026-10-07 02:30.10 4,111,792 new
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Directory C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData add
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Windows\SoftwareDistribution\DataStore\DataStore.edb 2026-10-07 02:06.46 36,700,160 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm 2026-10-07 02:06.46 16,384 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log 2026-10-07 02:06.46 1,310,720 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb 2026-10-07 02:12.57 262,144 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe File C:\Windows\SoftwareDistribution\ReportingEvents.log 2026-10-07 02:13.09 400,372 del
Операционная система Microsoft® Windows® C:\Windows\System32\svchost.exe File C:\Windows\System32\winevt\Logs\microsoft-windows-diagnosis-scripted%4operational.evtx 2026-10-05 22:03.02 69,632 add
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Directory C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.175_none_17ae9e046da28e97 del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache.v2\Legacy del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\CA del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Disallowed del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\Root del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\SmartCardRoot del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\trust del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Microsoft\SystemCertificates\TrustedPeople del
Операционная система Microsoft® Windows® C:\Windows\system32\svchost.exe Key HKU\S-1-5-21-2292890337-69778762-837601055-1001\Software\Policies\Microsoft\SystemCertificates del
Служба Windows® Search C:\Windows\system32\SearchIndexer.exe File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr 2026-10-07 02:04.48 36,678 old
Служба Windows® Search C:\Windows\system32\SearchIndexer.exe File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.6.gthr 2026-10-07 02:15.33 36,928 new
Opened Ports\ mod
- - TCP 10.0.2.15 49698 104.18.12.149 80 TIME_WAIT del
- - TCP 10.0.2.15 49699 104.18.12.149 443 TIME_WAIT del
- - TCP 10.0.2.15 49700 104.18.10.31 443 TIME_WAIT del
- - TCP 10.0.2.15 49701 172.184.231.67 443 TIME_WAIT del
- - TCP 10.0.2.15 49703 74.178.240.51 443 TIME_WAIT del
- - TCP 10.0.2.15 49704 20.52.64.203 443 TIME_WAIT del
- - TCP 10.0.2.15 49705 4.207.44.77 443 TIME_WAIT del